Junglewise Threat Intelligence

CVE-2026-16416: Google Chrome integer overflow in Chromecast

CVE-2026-16416 · Severity: info · Published 2026-07-21

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Chromecast component of Google Chrome. This flaw could allow a local attacker to bypass the browser's security sandbox, which is designed to keep malicious code isolated from the rest of the computer. If successfully exploited, this could lead to unauthorized access to the underlying operating system or sensitive user data.

Technical details

This vulnerability is classified as an integer overflow (CWE-190) within the Chromecast component of Google Chrome. The flaw is triggered when the component processes specially crafted malicious network traffic. A local attacker can leverage this overflow to achieve a sandbox escape, potentially leading to arbitrary code execution outside of the restricted browser environment. The issue was addressed in Chrome version 150.0.7871.182 for Windows and Mac, and 150.0.7871.181 for Linux. Access to specific bug details remains restricted by the vendor to prevent widespread exploitation until a majority of users have updated.

Affected products

  • Google Chrome Prior to 150.0.7871.182

Timeline

  • 2026-06-05: disclosed: Reported to Google internally
  • 2026-07-21: patched: Fixed in Stable Channel Update 150.0.7871.182
  • 2026-07-21: advisory: NVD publication date

References

Related threats