Executive brief
A vulnerability in the Cast component of Google Chrome could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Google has released an update to address this issue.
Technical details
An inappropriate implementation vulnerability exists in the Cast component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies by enticing a user to visit a malicious HTML page. Successful exploitation enables the attacker to leak data from other origins, violating the Same-Origin Policy (SOP). The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
- 2026-07-30: disclosed: CVE published to NVD