Executive brief
Google Chrome contains an integer overflow vulnerability in its Chromecast component that could allow an attacker who has already compromised the browser's renderer process to execute arbitrary code outside the sandbox. This would enable an attacker to bypass Chrome's security sandbox and gain full access to the user's system, potentially stealing data or installing malware.
Technical details
An integer overflow vulnerability exists in the Chromecast component of Google Chrome prior to version 152.0.7977.65. The vulnerability requires the attacker to have already compromised the renderer process, then craft a malicious HTML page to trigger the integer overflow. Upon successful exploitation, an attacker can execute arbitrary code outside Chrome's security sandbox. The vulnerability is classified as High severity and was fixed in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65