Junglewise Threat Intelligence

CVE-2026-10888: Google Chrome use after free in Cast Streaming

CVE-2026-10888 · Severity: info · CVSS 10 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability exists in Google Chrome's Cast Streaming component, which is used to share content from a browser to other devices like smart TVs. An attacker on the same local network could send malicious network traffic to take full control of a user's computer. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the Cast Streaming component of Google Chrome. The flaw is triggered by processing malicious network traffic sent from the same local network segment. By exploiting this memory corruption issue, an attacker can achieve arbitrary code execution (ACE) within the context of the browser. The vulnerability was reported by Google and is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux. Chromium developers have assigned this a 'Critical' severity rating.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-23: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats