Junglewise Threat Intelligence

CVE-2026-13940: Google Chrome uninitialized use in Cast

CVE-2026-13940 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Cast functionality, which is used to stream content to other devices like smart TVs. An attacker on the same local network could exploit this flaw to access sensitive information stored in the browser's memory. This could lead to the exposure of private data or internal system information, though it requires the attacker to be physically or logically near the user's network.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) exists within the Cast component of Google Chrome. The flaw is triggered when the application fails to properly initialize memory before it is used in a cast-related operation. An attacker located on the same local network segment (adjacent) can send specially crafted network traffic to the vulnerable client. Successful exploitation allows the attacker to read uninitialized process memory, potentially leaking sensitive information. The issue is resolved in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats