Executive brief
A security vulnerability exists in the Google Chrome web browser's Cast component, which is used for streaming content to other devices. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the attack is limited by the browser's security sandbox, it still represents a significant risk to system integrity and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of Cast-related objects, allowing a remote attacker to achieve arbitrary code execution within the renderer process sandbox. Exploitation requires the victim to navigate to a malicious web page (network-based attack vector). The vulnerability is tracked as CWE-416 and was addressed in Chrome version 150.0.7871.128.
Affected products
- Google Chrome prior to 150.0.7871.128
Timeline
- 2026-06-10: other: Reported to Google
- 2026-07-16: patched: Fixed in stable channel update 150.0.7871.128/.129
- 2026-07-20: disclosed: NVD publication date