Executive brief
A security vulnerability has been identified in the Chromecast component of Google Chrome. This flaw could allow a local attacker to bypass the browser's security sandbox, which is designed to keep malicious code isolated from the rest of the computer. If successfully exploited, this could lead to unauthorized access to the underlying operating system or sensitive user data.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the Chromecast component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be triggered by malicious network traffic. A local attacker could leverage this weakness to achieve a sandbox escape, potentially gaining elevated privileges on the host system. The issue was addressed in Google Chrome version 150.0.7871.182 for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 150.0.7871.182
Timeline
- 2026-05-28: disclosed: Reported by Google internal researchers
- 2026-07-21: patched: Fixed in Stable Channel Update 150.0.7871.182
- 2026-07-21: advisory