Executive brief
A security vulnerability exists in the Chromecast component of Google Chrome for Android, Linux, and ChromeOS. This flaw could allow an attacker on the same local network to execute unauthorized code within the browser's restricted security sandbox. While the sandbox limits the attacker's reach, such an exploit could disrupt browser operations or be used as a stepping stone for further attacks.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Chromecast component of Google Chrome. The vulnerability is triggered by processing malicious network traffic, allowing an attacker on the same local network (adjacent) to achieve arbitrary code execution within the Chromium sandbox. While the attack requires high complexity, it does not require user interaction or elevated privileges. The issue affects versions prior to 148.0.7778.179 on Android, Linux, and ChromeOS. Users are advised to update to the latest stable channel release to mitigate this risk.
Affected products
- Google Chrome prior to 148.0.7778.179
Timeline
- 2026-03-25: disclosed: Reported by Google internal researchers
- 2026-05-19: patched: Fixed in stable channel update 148.0.7778.179
- 2026-05-20: advisory: NVD publication date