Executive brief
Google Chrome's Cast feature, which allows users to share content from their browser to other screens, contains a security flaw. A remote attacker could use a specially designed website to trick the browser into leaking sensitive data from other websites the user has open. This could lead to the unauthorized exposure of personal information or session data across different web services.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker via a crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date