CVE-2026-11170

Description

An inappropriate implementation flaw was found in the Chromoting component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=502322596

Statement

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands; Read Application Data; DoS: Crash, Exit, or Restart

An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable the normal security checks being performed by the operating system or surrounding environment. Other pre-existing weaknesses can turn into security vulnerabilities if they occur while operating at raised privileges.

Frequently Asked Questions

Want to get errata notifications? Sign up here.