Junglewise Threat Intelligence

CVE-2026-13796: Google Chrome integer overflow in Chromecast sandbox escape

CVE-2026-13796 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Chromecast component contains a security vulnerability that could allow an attacker to bypass the browser's security sandbox. This component is responsible for media streaming and casting functionality within the browser. If exploited, an attacker who has already gained a foothold in the browser's rendering process could potentially gain broader access to the underlying operating system or user data.

Technical details

An integer overflow vulnerability exists in the Chromecast component of Google Chrome. The flaw is triggered via a crafted HTML page and requires the attacker to have already compromised the renderer process. Successful exploitation allows the attacker to perform a sandbox escape, potentially leading to arbitrary code execution outside of the restricted browser environment. This issue is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) and was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-03-11: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 stable channel update
  • 2026-06-30: advisory

References

Related threats