MEDIUM
CVE-2026-12444
CVSS
5.5
Description
Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: High)
Summary dbcve.org
This is an out-of-bounds read vulnerability in Chrome's Chromoting (remote desktop) component on Windows. A local attacker can exploit this by tricking a user into opening a malicious file, allowing them to read beyond allocated memory boundaries and potentially extract sensitive data from the process memory space.
Mitigation
Update Google Chrome to version 149.0.7827.155 or later. Organizations should deploy this update through their standard patch management processes and verify completion across Windows endpoints.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.14%
Probability of exploitation in next 30 days
4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.