CVE-2026-78913

Google · Chrome

A use-after-free vulnerability in the Chromoting component of Google Chrome allows remote attackers to execute arbitrary code via crafted network traffic.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome, identified as CVE-2026-78913, could allow a remote, unauthenticated attacker to execute arbitrary code on affected systems.

Vulnerability

This flaw is a use-after-free vulnerability (CWE-416) within the Chromoting component. It permits an unauthenticated remote attacker to trigger memory corruption and potentially achieve arbitrary code execution outside the browser sandbox by sending specifically crafted network traffic.

Business impact

The vulnerability carries a CVSS score of 8.1, reflecting the significant risk of remote code execution. Successful exploitation could lead to a full system compromise, unauthorized data access, and the potential for lateral movement within the network. Although the attack requires high complexity, the potential for total impact on confidentiality, integrity, and availability necessitates urgent patching.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately to incorporate the vendor-provided security fixes.

Proactive Monitoring: Monitor network traffic for anomalous patterns directed at Chromoting services and review system access logs for signs of unexpected process execution.

Compensating Controls: Ensure that endpoint protection software is active and consider restricting network access to Chromoting services if they are not required for business operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential remote code execution, all organizations utilizing Google Chrome should prioritize updating to the latest stable release. System administrators should verify that all managed browser instances are updated to version 152.0.7977.65 or higher to eliminate this risk entirely.

More Google CVEs

Sources