Executive brief
A critical vulnerability was identified in Google Chrome's Cast component, which is used for streaming media to other devices. An attacker on the same local network could send malicious traffic to a user's browser to cause a system crash or potentially take control of the application. This could lead to the theft of sensitive information or unauthorized access to the user's device.
Technical details
A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory pointers during the processing of network traffic related to media casting. An attacker situated on the same local network segment can exploit this by sending specially crafted network packets, leading to heap corruption. This can result in a browser crash (Denial of Service) or potentially arbitrary code execution within the context of the browser process. The vulnerability is mitigated by updating to version 149.0.7827.53 or later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-14: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date