Junglewise Threat Intelligence

CVE-2026-14063: Google Chrome out of bounds read in Chromecast

CVE-2026-14063 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Chromecast component of the Google Chrome browser. This flaw could allow a local attacker to access sensitive information stored in the computer's memory by sending specially crafted network traffic. While the risk is considered low, it could potentially expose private data to unauthorized parties on the same local network.

Technical details

This vulnerability is classified as an out-of-bounds read within the Chromecast component of Google Chrome. The flaw is triggered when the component processes malicious network traffic, leading to an unauthorized read of memory beyond the intended buffer. A local attacker (on the same network or with local access) can exploit this to leak sensitive information from the browser's process memory. The issue was addressed in Google Chrome version 150.0.7871.47. The vulnerability is tracked as CVE-2026-14063 and was assigned a 'Low' severity rating by the Chromium security team.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Google Chrome release advisory published
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47

References

Related threats