Description
Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Published: 2026-08-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the Chromoting component of Google Chrome versions earlier than 151.0.7922.173. It allows a remote attacker to send specially crafted network traffic that frees a memory object and then re‑uses its pointer to execute code outside the browser sandbox. The flaw is classified as CWE‑416 and can give attackers full control over the user’s system, compromising confidentiality, integrity and availability.

Affected Systems

The flaw affects desktop editions of Google Chrome running Windows, macOS or Linux where the Chromoting feature (remote desktop/remote assistance) is enabled. All Chrome versions released before 151.0.7922.173 are vulnerable; the patched release begins with 151.0.7922.173.

Risk and Exploitability

The bug has a CVSS score of 8.8, indicating a critical severity. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the fact that it can be exploited through network traffic makes it high risk. Attackers could hijack the browser process, escape the sandbox, and run arbitrary code on the victim’s machine.

Generated by OpenCVE AI on August 21, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.173 or newer.
  • Enable automatic updates or use a managed rollout to ensure timely patching.
  • If remote desktop functionality is not required, disable Chromoting or block its network traffic.

Generated by OpenCVE AI on August 21, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4758-1 chromium security update
Debian DSA Debian DSA DSA-6476-1 chromium security update
History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Vulnerability Allowing Remote Code Execution in Chrome

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Vulnerability Allowing Remote Code Execution in Chrome

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 20 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-21T18:47:55.270Z

Reserved: 2026-08-18T19:28:07.379Z

Link: CVE-2026-76017

cve-icon Vulnrichment

Updated: 2026-08-21T18:47:23.652Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T21:17:09.800

Modified: 2026-08-25T16:37:12.347

Link: CVE-2026-76017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:30:17Z

Weaknesses