Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Cast component, which is used for streaming content to other devices. A remote attacker could use a specially crafted website to trick the browser into leaking sensitive data from other websites the user is visiting. This could lead to the unauthorized exposure of private information or session data across different web domains.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies by providing specially crafted input through an HTML page. If successful, an attacker can read data from origins other than the one serving the malicious page, leading to information disclosure. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date