ZeroHour

CVE-2026-84334

mass

Incorrect Authorization in Chrome Chromoting Enables Local Sandbox Escape on Windows

CVSS 3.1
8.1 high
EPSS
<1%p0
Published
()
Modified
AI analysis

An incorrect authorization flaw (CWE-863) in the Chromoting component of Google Chrome on Windows — the technology behind Chrome Remote Desktop — fails to properly enforce authorization across the sandbox boundary. A local attacker with a program already running on the affected Windows machine can exploit it to execute arbitrary code outside the browser sandbox. Successful exploitation yields code execution beyond Chrome's sandbox containment (with confidentiality, integrity, and availability impact on the host), though it requires local access, involves high attack complexity, and Chromium rates it only Medium severity. All Google Chrome installations on Windows prior to 152.0.7977.75 are affected; other platforms are not named in the advisory. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.1% probability of exploitation within 30 days.

What to do: Update Google Chrome on Windows to version 152.0.7977.75 or later, verifying the version via chrome://settings/help or your software deployment tooling. Because exploitation requires a local attacker with an already-running program, standard endpoint hygiene — restricting execution of untrusted local executables — reduces practical risk. No workaround is known for this authorization flaw, so patching is the primary remediation.

Affected
Google Chrome (Windows)All versions prior to 152.0.7977.75
Estimated exposure
mass≈1 billion+ Chrome-on-Windows installations (Chrome has roughly 3 billion users and Windows dominates desktop) — Chrome's global install base is estimated at ~3 billion users, and Windows accounts for the majority of desktop OS share, so affected Windows installations plausibly number in the hundreds of millions to over a billion, even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.