Executive brief
A security issue was identified in Google Chrome's Chromecast component that could allow an attacker to bypass certain navigation restrictions. This vulnerability requires an attacker to have already partially compromised the browser's rendering process, typically through a malicious website. If successful, the attacker could force the browser to navigate to restricted pages or locations it should not be able to access.
Technical details
A navigation restriction bypass vulnerability exists in the Chromecast component of Google Chrome prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that fails to properly enforce security boundaries during page transitions. An attacker who has already achieved code execution within a compromised renderer process can exploit this by serving a specially crafted HTML page. This allows the attacker to bypass intended navigation constraints, potentially leading to further sandbox escapes or unauthorized access to internal browser interfaces. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched