Junglewise Threat Intelligence

CVE-2026-12014: Google Chrome use after free in Cast

CVE-2026-12014 · Severity: info · CVSS 8.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the Cast component of Google Chrome, which is used for streaming media to other devices. An attacker on the same local network could send malicious traffic to trigger a memory error, potentially allowing them to break out of the browser's security sandbox. This could lead to unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome. The flaw is triggered by malicious network traffic sent from the local network segment (adjacent). By exploiting this memory corruption issue, an attacker can potentially bypass the Chromium sandbox, leading to remote code execution outside of the restricted browser environment. The vulnerability was addressed in Chrome version 149.0.7827.115 for Windows and Mac, and 149.0.7827.114 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-19: other: Reported by Google researchers
  • 2026-06-11: patched: Stable channel update released
  • 2026-06-11: disclosed: Public advisory published

References

Related threats