Description
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Authorization Bypass
Action: Patch
AI Analysis

Impact

An incorrect authorization check in the Chromoting component of Google Chrome for Windows allows a local attacker to bypass system access restrictions by executing a local program. This flaw is marked as medium severity by Chromium and maps to CWE-863, which represents the use of insufficient authority for access control. If exploited, the attacker could gain elevated control over Chrome’s remote‑desktop capabilities, potentially accessing user sessions or sensitive data within the browser.

Affected Systems

Google Chrome on Windows versions older than 152.0.7977.65 is affected. Users running these outdated installs may trigger the issue by launching a local program that activates the Chromoting feature.

Risk and Exploitability

The vulnerability requires local code execution and does not depend on network access. The CVSS score of 7.1 indicates moderate-to-high severity. The EPSS score is < 1%, suggesting a low probability of exploitation in the wild. Because the issue is not listed in CISA’s KEV catalog, public exploitation probability is uncertain. However, a local attacker who has ability to run code on a user’s machine could immediately use the bypass to gain elevated Chrome Remote Desktop privileges. The medium severity rating indicates a meaningful risk in a compromised or privileged context.

Generated by OpenCVE AI on August 28, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later.
  • Disable the Chromoting feature if not required, for example via Settings > Remote or via group policy to block access to the Chrome Remote Desktop API.
  • Restrict execution of untrusted local programs and enforce least‑privilege permissions so that only trusted applications can invoke Chrome with remote‑desktop capabilities.

Generated by OpenCVE AI on August 28, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Fri, 28 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Chrome Chromoting

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T17:49:03.557Z

Reserved: 2026-08-25T06:03:51.254Z

Link: CVE-2026-78892

cve-icon Vulnrichment

Updated: 2026-08-28T16:29:29.794Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:46.510

Modified: 2026-08-31T18:57:12.673

Link: CVE-2026-78892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:45:03Z

Weaknesses