HomeSecurityOpenClaw Vulnerability: Critical flaw in Google Meet allows RCE

OpenClaw Vulnerability: Critical Gap in Google Meet Allows RCE

OpenClaw vulnerability CVE -2026-100599 allows execution of arbitrary processes on a connected Chrome node when the Google Meet add-on is active and the command is allowed. The vulnerability was fixed in version 2026.7.1, but installations that remain on an older version require immediate review.

The CVE listing rates the issue as high severity, with a CVSS 3.1 score of 8.8 and CVSS 4.0 score of 8.7. The CVEFeed listing, CVE-2026-100599, sourced by VulnCheck, describes a specific scenario that does not affect every OpenClaw installation, but can have significant consequences on affected devices.

See also: Google Home opens the door to Claude, OpenClaw and other MCP agents

OpenClaw vulnerability in Google Meet and Chrome node

How the OpenClaw vulnerability works

The problem is in the googlemeet.chrome. OpenClaw versions 2026.5.1 through 2026.7.0 do not pass Google Meet commands through the normal system.run. Thus, the audio command panel provided by the caller can reach the paired Chrome node without the additional filter that would require authorization.

For the attack to be practical, four conditions must exist: the Google Meet add-on must be enabled, a Chrome node must be associated, the googlemeet.chrome , and a tooling-enabled agent must be able to call it. The CVE description does not support the idea that any user or remote visitor can exploit the OpenClaw vulnerability without these settings.

When the scenario is feasible, the attacker can cause the node to execute processes of their choosing. The impact can extend to files, credentials, browser profiles, and device availability. The critical point is not a simple change to the Meet session, but the loss of the expected disjointed approval before an action with access to the operating system.

Administrators should review Gateway and Chrome node logs for unexpected command invocations, new connections, or processes started from the agent environment. If an affected configuration has been used, the technical team should consider the credentials that were available in the browser profile as potentially exposed and renew them after review.

Command approval mechanism in OpenClaw Chrome node

Which users are affected and what they should check

The report primarily concerns installations that use this integration and have opened the corresponding command on the node. Administrators should record the version, active add-ons, paired devices, and allowed commands, rather than assuming that the mere presence of OpenClaw is enough to create a risk.

The OpenClaw vulnerability is not addressed in the same way in every environment. On a home computer, disabling the add-on may be required, while in an organization, a parallel inventory of devices, their owners, and the data they accessed is required.

The preferred action is to upgrade to OpenClaw 2026.7.1 or a later supported version. The official OpenClaw 2026.7.1 release notes describe broader enhancements to authentication, authorization, and node management, without replacing local configuration control.

If the upgrade cannot be done immediately, CVE suggests removing googlemeet.chrome from the allowed commands or disabling the Google Meet add-on as a temporary measure. For the OpenClaw vulnerability, it is also useful to review paired devices and revoke connections that are no longer in use.

After installing the patch, verification should not be limited to the version number. It should include testing in a non-critical environment, confirming that the add-in is loaded with the expected permissions, and checking that an unauthorized call is stopped before it reaches the operating system. This avoids the false sense of security of a standard update.

See also: NVIDIA NemoClaw: Vulnerability allows websites to manipulate AI agents

OpenClaw protection by disabling dangerous commands

OpenClaw vulnerability shows the limit of automation

The SecNews technical team recommends that organizations treat each paired node as a privileged computer, not a mere peripheral in a conversation. Commands that can touch files, profiles, or credentials need minimal permissions, logging, and a clear revocation process.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: GhostApproval: Symlink vulnerabilities in AI coding agents

CVE-2026-100599 does not in itself prove that an exploit has been made in a real-world environment. However, it is a clear reminder that the OpenClaw vulnerability can occur when an automated command bypasses the approval point that is supposed to protect the user. Upgrading, limiting node commands, and regularly re-examining agents are key defenses against the OpenClaw vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS