Executive brief
Google Chrome contains a security vulnerability in its Chromecast component, which handles media streaming to external devices. If a user visits a malicious website, an attacker who has already compromised the browser's content rendering process could bypass security boundaries (the sandbox). This could allow the attacker to gain unauthorized access to the underlying operating system and the user's private data.
Technical details
A vulnerability exists in the Chromecast component of Google Chrome due to improper input validation (CWE-20). The flaw allows a remote attacker to perform a sandbox escape. The attack requires the adversary to have already achieved code execution within a compromised renderer process, typically via a separate vulnerability triggered by a crafted HTML page. By providing malicious input to the Chromecast interface, the attacker can break out of the restricted browser environment to execute commands with the privileges of the browser process. This issue is resolved in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-15: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: advisory: NVD publication date