Junglewise Threat Intelligence

CVE-2026-6317: Google Chrome use after free in Cast

CVE-2026-6317 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Cast component of Google Chrome, which is used for streaming media to other devices. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, this could allow the attacker to take control of the user's computer or execute unauthorized commands.

Technical details

A use-after-free vulnerability exists in the Cast component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media casting operations. A remote, unauthenticated attacker can exploit this by enticing a user to open a maliciously crafted HTML page. Successful exploitation can lead to arbitrary code execution within the context of the browser process. Google has addressed this issue in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-04-06: disclosed: Reported to Chrome by Google researchers.
  • 2026-04-15: patched: Fixed in Chrome Stable Channel Update 147.0.7727.101.
  • 2026-04-15: advisory: NVD publication date.

References