Junglewise Threat Intelligence

CVE-2026-10884: Google Chrome use after free in Chromecast sandbox escape

CVE-2026-10884 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability was identified in the Chromecast component of Google Chrome. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, an attacker could gain broader access to the underlying system, potentially leading to full system compromise or unauthorized data access.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromecast component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of specifically crafted HTML content. An attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to bypass the Chrome sandbox. This allows the attacker to execute arbitrary code with the privileges of the browser process or the underlying operating system. The vulnerability was reported by Google and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-17: disclosed: Reported by Google internally
  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats