Executive brief
A vulnerability in Google Chrome's Chromecast component could allow an attacker to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted malicious website. While the attacker must first compromise a specific part of the browser's internal processes, an exploit could lead to the exposure of private data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Chromecast component of Google Chrome. The flaw is reachable by a remote attacker who has already compromised the renderer process. By enticing a user to load a malicious HTML page, the attacker can trigger the memory safety error to read sensitive information from the process memory. This vulnerability was addressed in Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched