CVE-2026-14121
Critical · CVSS 9.8Google Chrome / Chromoting (Chrome Remote Desktop) — Use-After-Free (UAF) Remote Code Execution
- CVSS
- 9.8
- nvd
- EPSS
- 0.29%
- 21th pct
- KEV
- No
- Class
- kernel local
- CWE-416
Description
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
Search profile — drives PoC discovery
Symbols Chromotingchromotingremotingchrome_remote_desktopCRDUAFuse-after-freenetwork_traffic_handlerremoting::protocolremoting::host
Keywords CVE-2026-14121Chromoting use after freeChrome Remote Desktop UAF LinuxGoogle Chrome 150.0.7871.47 exploitChromium Chromoting RCECWE-416 Chrome Chromotingchromium issue 513789382Chrome Linux remote code execution Chromoting PoC
Versions: < 150.0.7871.47
References
Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z