Junglewise Threat Intelligence

CVE-2026-13884: Google Chrome integer overflow in Chromecast

CVE-2026-13884 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Chromecast component of Google Chrome. This flaw could allow a local attacker to execute unauthorized code on a user's system by sending specially crafted network traffic. Such an exploit could lead to a complete compromise of the device, potentially resulting in data theft or the installation of malicious software.

Technical details

An integer overflow vulnerability (CWE-122) exists in the Chromecast component of Google Chrome. The flaw is triggered when the component processes malicious network traffic, leading to a heap-based buffer overflow. A local attacker can leverage this to achieve arbitrary code execution within the context of the browser. The vulnerability was addressed in Google Chrome version 150.0.7871.47. While the Chromium project internally rated this as 'Medium' severity, the potential for code execution via network traffic is a significant security concern.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Google Chrome release advisory published.
  • 2026-06-30: patched: Fixed in Google Chrome version 150.0.7871.47.

References

Related threats