Description
Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-04
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a use‑after‑free flaw in the Chromecast component of Google Chrome versions earlier than 149.0.7827.53. An attacker with control of a compromised renderer process can craft a malicious HTML page that triggers the freed memory usage, enabling the attacker to escape the browser sandbox and execute code with the privileges of the host process. The flaw is defined as CWE‑416, a fundamental memory management error that directly compromises integrity and confidentiality.

Affected Systems

Google Chrome, the desktop stable channel, any installation running a version prior to 149.0.7827.53. The issue is limited to the Chromecast feature within the browser.

Risk and Exploitability

Chromium rates the issue as Critical, with a CVSS score of 8.3. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog, implying that no known exploits have been observed in the wild yet. However, the need to compromise the renderer process can be achieved by serving a malicious web page, so the likelihood of exploitation is non‑negligible for active users of the affected Chrome versions. The only effective defense is to remove the flaw via an official update.

Generated by OpenCVE AI on June 5, 2026 at 05:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later, which incorporates the security fix.
  • Ensure Chrome auto‑update is enabled so that future patches are applied automatically.
  • Restart the browser after updating to apply the changes.

Generated by OpenCVE AI on June 5, 2026 at 05:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chromecast Use‑After‑Free Enables Remote Sandbox Escape

Fri, 05 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T01:44:40.625Z

Reserved: 2026-06-04T17:05:55.395Z

Link: CVE-2026-10884

cve-icon Vulnrichment

Updated: 2026-06-05T01:39:52.216Z

cve-icon NVD

Status : Received

Published: 2026-06-04T23:16:49.763

Modified: 2026-06-05T02:16:50.843

Link: CVE-2026-10884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T05:30:32Z

Weaknesses