CVE-2026-84334
massIncorrect Authorization in Chrome Chromoting Enables Local Sandbox Escape on Windows
An incorrect authorization flaw (CWE-863) in the Chromoting component of Google Chrome on Windows — the technology behind Chrome Remote Desktop — fails to properly enforce authorization across the sandbox boundary. A local attacker with a program already running on the affected Windows machine can exploit it to execute arbitrary code outside the browser sandbox. Successful exploitation yields code execution beyond Chrome's sandbox containment (with confidentiality, integrity, and availability impact on the host), though it requires local access, involves high attack complexity, and Chromium rates it only Medium severity. All Google Chrome installations on Windows prior to 152.0.7977.75 are affected; other platforms are not named in the advisory. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.1% probability of exploitation within 30 days.
What to do: Update Google Chrome on Windows to version 152.0.7977.75 or later, verifying the version via chrome://settings/help or your software deployment tooling. Because exploitation requires a local attacker with an already-running program, standard endpoint hygiene — restricting execution of untrusted local executables — reduces practical risk. No workaround is known for this authorization flaw, so patching is the primary remediation.
| Google Chrome (Windows) | All versions prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.