Executive brief
Google Chrome's Cast feature, which allows users to stream content to other devices like smart TVs, contains a security vulnerability. An attacker located on the same local network (such as public Wi-Fi) could exploit this flaw to intercept sensitive data from other websites you have open. This could lead to the exposure of private information that is normally protected by browser security boundaries.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw stems from insufficient validation of untrusted input received over the network. An attacker positioned on the same local network segment can craft malicious network traffic to exploit this weakness, potentially bypassing cross-origin resource sharing (CORS) or similar site-isolation policies to leak sensitive data. The vulnerability is addressed in Google Chrome version 151.0.7922.72. The attack requires no prior authentication but does require the attacker to be on the same adjacent network as the victim.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date