Executive brief
A vulnerability exists in the Chromecast component of Google Chrome that could allow an attacker to bypass security boundaries. If a user visits a specially crafted malicious website, an attacker who has already compromised the browser's content rendering process could escape the restricted 'sandbox' environment. This could lead to unauthorized access to the underlying operating system and sensitive user data.
Technical details
An integer overflow vulnerability exists in the Chromecast component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when processing a crafted HTML page. A remote attacker who has already achieved code execution within the compromised renderer process can exploit this overflow to perform a sandbox escape. This allows the attacker to break out of the browser's restricted environment and execute commands with the privileges of the browser process on the host system. The vulnerability was reported by Google and is addressed in the Chrome 149 stable channel update.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-06: disclosed: Reported to Chromium project
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-04: advisory: NVD publication date