Junglewise Threat Intelligence

CVE-2026-14093: Google Chrome use after free in Cast

CVE-2026-14093 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the Cast component of Google Chrome, which is used for streaming media to other devices. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering process could potentially bypass security protections (the sandbox) to gain further access to the underlying system. This could lead to unauthorized access to local data or the ability to execute commands outside of the browser's restricted environment.

Technical details

A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of Cast-related objects. An attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to perform a sandbox escape. This requires the victim to navigate to a malicious HTML page. The vulnerability is mitigated by Chrome's multi-process architecture, and Google classifies the severity as Low. Users should update to version 150.0.7871.47 or later to resolve the issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats