Junglewise Threat Intelligence

CVE-2026-13801: Google Chrome integer overflow in Chromecast

CVE-2026-13801 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Chromecast component of Google Chrome. This flaw could allow a remote attacker who has already partially compromised the browser's rendering process to bypass security boundaries (the sandbox). If successful, an attacker could gain broader access to the underlying operating system, potentially leading to unauthorized data access or full system control.

Technical details

An integer overflow vulnerability exists in the Chromecast component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser processes a specially crafted HTML page. An attacker who has already achieved code execution within the renderer process can exploit this overflow to perform a sandbox escape. This allows the attacker to execute arbitrary code with the privileges of the browser process rather than the restricted renderer process. Google has addressed this in the stable channel update to version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-08: disclosed: Reported to Google internally
  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 stable channel update
  • 2026-06-30: advisory

References

Related threats