Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14084

CVE-2026-14084: Google Chrome RCE Vulnerability

CVE-2026-14084 is a remote code execution vulnerability in Google Chrome's Chromoting feature caused by insufficient input validation. Attackers can exploit heap corruption through malicious network traffic. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-14084 Overview

CVE-2026-14084 is an input validation vulnerability in the Chromoting component of Google Chrome. The flaw affects versions prior to 150.0.7871.47 and stems from insufficient validation of untrusted input received over the network. A remote attacker can send crafted network traffic to trigger heap corruption in the browser process. Successful exploitation requires user interaction. The weakness is categorized under [CWE-20: Improper Input Validation]. Google's Chromium security team assigned an internal severity of Low, while the National Vulnerability Database rates the issue as High.

Critical Impact

A remote attacker can trigger heap corruption in Chrome's Chromoting component via malicious network traffic, potentially leading to code execution with impact on confidentiality, integrity, and availability.

Affected Products

  • Google Chrome versions prior to 150.0.7871.47
  • Chromoting (Chrome Remote Desktop) component within affected Chrome builds
  • Desktop platforms served by the Chrome Stable channel

Discovery Timeline

  • 2026-06-30 - CVE-2026-14084 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-14084

Vulnerability Analysis

The vulnerability resides in Chromoting, the code path that powers Chrome Remote Desktop. Chromoting processes network messages exchanged between remote peers to negotiate sessions and transport input, video, and control data. The component fails to sufficiently validate untrusted input arriving over the network. When malformed data is parsed, the resulting state corrupts heap memory managed by the browser process.

Heap corruption in a browser process can be leveraged to overwrite adjacent objects, function pointers, or metadata used by the allocator. Exploitation requires user interaction, consistent with the CVSS User Interaction Required designation, meaning the victim must initiate or accept a Chromoting-related action. Because the attack traverses the network, no local access or prior privilege is needed by the attacker.

Root Cause

The root cause is improper input validation [CWE-20] on network messages consumed by Chromoting. The component accepts attacker-controlled fields without enforcing the size, type, or structural constraints required by downstream memory operations. This gap allows out-of-bounds writes or mismanaged allocations that corrupt the heap.

Attack Vector

An attacker delivers crafted network traffic to a Chrome instance running Chromoting. Because interaction is required, the attacker likely relies on a user initiating a Chrome Remote Desktop session or connecting to an attacker-controlled peer. Once the malicious frames are processed, memory corruption occurs inside the browser process. No proof-of-concept exploit is currently published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

// No verified proof-of-concept is available for CVE-2026-14084.
// Refer to the Chromium issue tracker entry 513138148 for technical details
// once Google removes access restrictions.

Detection Methods for CVE-2026-14084

Indicators of Compromise

  • Chrome browser or renderer process crashes referencing Chromoting or remoting_* modules on hosts running vulnerable Chrome builds.
  • Unexpected outbound or inbound connections to Chrome Remote Desktop relay endpoints from users who do not normally use the feature.
  • Chrome versions below 150.0.7871.47 reported by endpoint inventory or browser management tooling.

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any build earlier than 150.0.7871.47.
  • Correlate browser crash telemetry with Chromoting session activity to surface potential exploitation attempts.
  • Monitor for anomalous Chrome Remote Desktop usage patterns, particularly sessions initiated with unknown external peers.

Monitoring Recommendations

  • Ingest Chrome update and version telemetry into a centralized logging pipeline to track patch compliance.
  • Alert on repeated browser process crashes on the same host within short time windows.
  • Track DNS and network flows to Chrome Remote Desktop infrastructure to detect abuse.

How to Mitigate CVE-2026-14084

Immediate Actions Required

  • Update Google Chrome to version 150.0.7871.47 or later on all managed endpoints.
  • Restart Chrome after the update to ensure the patched binaries are loaded.
  • Disable Chrome Remote Desktop for user populations that do not require the feature until patching is verified.

Patch Information

Google released the fix in the Chrome Stable channel update announced on the Google Chrome Update Announcement. Additional context is tracked in the Chromium Issue Tracker Entry. Enterprises should push the update through their standard Chrome management channel, such as Chrome Browser Cloud Management or platform-specific software distribution.

Workarounds

  • Restrict use of Chrome Remote Desktop through enterprise policy until endpoints are updated.
  • Apply network egress controls to limit which hosts can reach Chrome Remote Desktop relays.
  • Require least-privilege user accounts for browsing to reduce the impact of any browser process compromise.
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Windows: query the installed Chrome version from the registry
reg query "HKLM\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# macOS: read the CFBundleShortVersionString from the Chrome bundle
defaults read "/Applications/Google Chrome.app/Contents/Info.plist" CFBundleShortVersionString

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.