Executive brief
A security vulnerability in Google Chrome's Cast feature could allow a malicious website to bypass the browser's Same Origin Policy. This policy is a fundamental security control that prevents websites from accessing data from other sites. If exploited, a malicious site could potentially interact with or access information from other open websites or services that the user did not intend to share.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by convincing a user to visit a specially crafted HTML page. By bypassing SOP, the attacker's site could potentially read data from or perform actions on behalf of other origins. This issue was addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux. The vulnerability is categorized by Chromium as 'Low' severity.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: CVE published in NVD