Junglewise Threat Intelligence

CVE-2026-11276: Google Chrome DAC bypass in Cast

CVE-2026-11276 · Severity: info · CVSS 3.1 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in the Google Chrome Cast component could allow an attacker on the same local network to bypass security controls. This component is responsible for streaming media from the browser to other devices. An exploit could allow an unauthorized user to interact with or access features that should normally be restricted by access control settings.

Technical details

An inappropriate implementation vulnerability exists in the Cast component of Google Chrome. The flaw is rooted in how the component handles discretionary access control (DAC) for network-based requests. An attacker situated on the same local network segment can send specially crafted network traffic to bypass these access controls. This could lead to unauthorized access to Cast-related functionality or data. The vulnerability is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: NVD publication date.

References

Related threats