Executive brief
A security vulnerability in the Chromecast component of Google Chrome could allow an attacker on the same local network to inject malicious scripts or content into a privileged browser page. This could potentially lead to unauthorized actions or the theft of information within the browser session. Users should update Google Chrome to version 151.0.7922.72 or later to mitigate this risk.
Technical details
An insufficient policy enforcement vulnerability exists in the Chromecast component of Google Chrome prior to version 151.0.7922.72. The flaw allows an attacker located on the same local network segment (Layer 2) to send malicious network traffic that results in the injection of arbitrary HTML or scripts into a privileged browser page. This is a cross-site scripting (XSS) class vulnerability where the root cause is a failure to strictly enforce security policies on incoming Chromecast-related data. An attacker could leverage this to execute code in the context of a sensitive internal page, though it requires the attacker to be on the same network as the victim. The issue is resolved in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date