CVE-2026-8586

Description

An inappropriate implementation flaw was found in the Chromoting component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=499154022

Statement

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Access control checks for specific user data or functionality can be bypassed.

Access Control

Technical Impact: Gain Privileges or Assume Identity

Horizontal escalation of privilege is possible (one user can view/modify information of another user).

Access Control

Technical Impact: Gain Privileges or Assume Identity

Vertical escalation of privilege is possible if the user-controlled key is actually a flag that indicates administrator status, allowing the attacker to gain administrative access.

Frequently Asked Questions

Want to get errata notifications? Sign up here.