Junglewise Threat Intelligence

CVE-2026-13798: Google Chrome heap buffer overflow in Chromecast

CVE-2026-13798 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Chromecast component of Google Chrome. This flaw could allow a malicious website to break out of the browser's security sandbox if the attacker has already compromised the page rendering process. Successful exploitation could lead to unauthorized access to the underlying operating system and user data.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Chromecast component of Google Chrome prior to version 150.0.7871.47. The vulnerability is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this overflow to bypass the Chromium sandbox. This could lead to full system compromise or arbitrary code execution outside of the browser's restricted environment. Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-02: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats