Executive brief
A vulnerability exists in the Cast Receiver component of Google Chrome, which is used to receive and display content streamed from other devices. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's device. While the impact is limited by Chrome's security sandbox, it could still lead to unauthorized actions or further exploitation of the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Cast Receiver component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific web content. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chrome renderer sandbox. The issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory