Security Advisory Desk
unratedQCS priority 70/100Microsoft

CVE-2026-76017: Chromium CVE-2026-76017: Use after free in Chromoting

A security vulnerability called CVE-2026-76017 was found in Chromium, the open-source project behind Google Chrome and Microsoft Edge's web engine. This vulnerability involves a "use after free" error in the remote desktop component called Chromoting. Microsoft Edge (Chromium-based) has incorporated the Chromium updates that fix this issue. Users should update to the latest Microsoft Edge version 151.0.4129.107 or later to be protected.

Published 8/9/2026, 7:00:00 amVerified 13/9/2026, 7:27:07 pmRevision 1
Microsoft unrated network security advisory visual

In plain language

What this advisory means

A security vulnerability called CVE-2026-76017 was found in Chromium, the open-source project behind Google Chrome and Microsoft Edge's web engine. This vulnerability involves a "use after free" error in the remote desktop component called Chromoting. Microsoft Edge (Chromium-based) has incorporated the Chromium updates that fix this issue. Users should update to the latest Microsoft Edge version 151.0.4129.107 or later to be protected.

Technical explanation

How the issue affects the environment

CVE-2026-76017 is a use-after-free vulnerability in the Chromoting module of Chromium. Use-after-free errors happen when software continues to use memory after it has been freed, potentially allowing attackers to execute arbitrary code or cause crashes. The Chromium project disclosed this vulnerability and released updates that address this flaw. Microsoft Edge (Chromium-based) includes this fix starting with version 151.0.4129.107, which is based on Chromium version 151.0.7922.174. The update mitigates the security risk by correcting the memory handling in Chromoting.

Operational impact

Why teams should care

Exploitation of this vulnerability could allow attackers to execute arbitrary code remotely or crash the browser, leading to potential data breaches or denial of service. For organizations relying on Microsoft Edge for web access, running vulnerable versions may increase risk. Updating to the fixed version improves security posture against remote code execution threats exploiting this flaw.

Immediate action

Update Microsoft Edge (Chromium-based) to version 151.0.4129.107 or later, which contains the Chromium fix for CVE-2026-76017 in the Chromoting component.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions151.0.4129.107

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Microsoft Security Response Center advisory for CVE-2026-76017.
  • Microsoft Edge version 151.0.4129.107 includes the Chromium update fixing the vulnerability.
  • Google Chrome Releases detail the Chromium fix for this CVE.
  • Microsoft Security Update Guide announcement confirming Edge is no longer vulnerable at specified version.

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source