Executive brief
Google Chrome is a widely used web browser that includes 'Cast' functionality for streaming content to other devices. A security flaw in this component could allow an attacker on the same local network to execute unauthorized code on a user's computer. While the attack is contained within a security sandbox, it could still lead to service disruptions or be used as a stepping stone for further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome. The flaw is triggered by the processing of malicious network traffic sent from the same local network segment (Adjacent vector). An unauthenticated attacker can exploit this memory corruption issue to achieve arbitrary code execution within the browser's sandbox environment. The vulnerability is mitigated by the sandbox architecture, which limits the attacker's access to the underlying operating system. Users should update to version 147.0.7727.138 or later to resolve the issue.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-06: disclosed: Reported to Chromium by Google researchers
- 2026-04-28: patched: Fixed in Stable Channel Update 147.0.7727.138
- 2026-04-28: advisory