Junglewise Threat Intelligence

CVE-2026-13804: Google Chrome use after free in Chromecast

CVE-2026-13804 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Chromecast component of Google Chrome. This flaw could allow a remote attacker who has already partially compromised the browser to bypass security restrictions (the sandbox) that normally isolate web pages from the rest of the computer. If successfully exploited via a specially crafted website, an attacker could gain broader access to the underlying system, potentially leading to unauthorized data access or further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromecast component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific content, leading to a memory corruption condition. An attacker who has already achieved code execution within a compromised renderer process can exploit this vulnerability by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-12: disclosed: Reported to Google by internal researchers.
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47.
  • 2026-06-30: advisory

References

Related threats