Junglewise Threat Intelligence

CVE-2026-10926: Google Chrome use after free in Cast

CVE-2026-10926 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Cast component of Google Chrome, which is used for streaming media to other devices. An attacker on the same local network could exploit this flaw to take control of a user's computer or execute unauthorized commands. This could lead to the theft of sensitive data or a complete compromise of the affected system.

Technical details

A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome. The flaw is triggered when the application attempts to use memory that has already been freed, specifically during the processing of network traffic related to Cast functionality. An attacker situated on the same local network segment can exploit this by sending specially crafted network packets to a vulnerable client. Successful exploitation can lead to arbitrary code execution (ACE) within the context of the browser process. The vulnerability is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-06: disclosed: Reported by Google internally
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats