Description
Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-04
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow in the Chromecast component of Google Chrome allows a malicious attacker who has already compromised the renderer process to potentially escape the sandbox and execute code with higher privileges. This weakness falls under CWE-472 and is characterized by a failure to properly validate arithmetic bounds, giving an attacker the ability to influence memory access patterns. The consequence of a successful escape is the ability for the attacker to run arbitrary code, modify system files, or gain persistence within the affected system.

Affected Systems

All desktop installations of Google Chrome that are running a version earlier than 149.0.7827.53 are affected. This includes Windows, macOS, Linux, and ChromeOS systems that have not applied the latest stable update. The vulnerability is tied to the Chromecast feature, so any user who has Chromecast functionality enabled in the browser is at risk.

Risk and Exploitability

The flaw is rated as high severity by Chromium, and the CVSS score is 8.3. The EPSS score is unavailable, indicating limited public data on exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have initial access to the renderer process, which could be achieved through a malicious web page or compromised site. Once the overflow is triggered, sandbox escape is possible, potentially leading to full system compromise. The attack vector is inferred to be remote via crafted HTML content, as the description references a crafted HTML page.

Generated by OpenCVE AI on June 5, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to the latest stable version (149.0.7827.53 or newer) as this release contains the patch for the integer overflow.
  • If an immediate update is not possible, disable Chromecast functionality in Chrome via policy or flag to eliminate the attack surface until a fix is applied.
  • Continuously monitor browsers for unauthorized renderer processes or crashes that could indicate exploitation attempts, and apply additional security controls such as endpoint protection and intrusion detection.

Generated by OpenCVE AI on June 5, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 06:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Fri, 05 Jun 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T01:41:09.540Z

Reserved: 2026-06-04T17:06:07.483Z

Link: CVE-2026-10924

cve-icon Vulnrichment

Updated: 2026-06-05T01:38:42.859Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-04T23:16:54.753

Modified: 2026-06-05T15:02:34.977

Link: CVE-2026-10924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T06:00:06Z

Weaknesses