Junglewise Threat Intelligence

CVE-2026-14048: Google Chrome use after free in Chromecast

CVE-2026-14048 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A memory management vulnerability exists in the Chromecast component of Google Chrome. An attacker on the same local network could use a malicious device to access sensitive information from the browser's memory. This could lead to the exposure of private data or internal system details.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the Chromecast component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory pointers during interactions with peripherals on the local network segment. An attacker with physical or network adjacency can leverage a malicious peripheral to trigger the memory corruption, potentially leading to an out-of-bounds read of sensitive process memory. This issue is mitigated by the requirement for local network access and was assigned a 'Low' severity rating by the Chromium project. Users should update to version 150.0.7871.47 or later to resolve the issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats