Description
Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
Published: 2026-06-11
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the Cast component of Google Chrome prior to version 149.0.7827.115. The flaw can allow a malicious actor who controls traffic on the same local network segment to inject crafted packets that are processed by the casting service, potentially causing the Cast process to use deallocated memory. This can lead to a sandbox escape, elevating privileges within the Chrome sandbox and possibly enabling broader compromise of the host system. The Chromium project has classified this issue as High severity. Based on the description, the vulnerable functionality is tied to local network interaction with Chrome’s Cast feature.

Affected Systems

The vulnerability affects all installations of Google Chrome that are running a version earlier than 149.0.7827.115, regardless of the operating system. Users must be aware that any local network device capable of interacting with the Chrome Cast protocol could serve as the attacker. The flaw is specific to the Cast functionality and does not impact other Chrome components.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw carries a high severity rating and requires a malicious actor to be on the same local network segment delivering specially crafted network traffic to the Cast service. Successful exploitation requires that the victim’s Chrome instance be actively listening for Cast traffic and that the attacker can inject packets before the vulnerable memory is freed. While the technical condition to exploit the use‑after‑free exists, no publicly disclosed exploit code has been reported, but the risk remains significant for environments where local network traffic is not tightly controlled.

Generated by OpenCVE AI on June 11, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 149.0.7827.115 or later
  • Disable the Cast feature or restrict local network access to Chrome’s Cast endpoint if an upgrade is not immediately possible
  • Enforce local network segmentation or firewall rules to block malicious traffic aimed at the Cast service

Generated by OpenCVE AI on June 11, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Cast Allowing Sandbox Escape via Local Network Traffic

Thu, 11 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 11 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-11T20:48:07.375Z

Reserved: 2026-06-11T18:16:04.221Z

Link: CVE-2026-12014

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-11T22:16:53.933

Modified: 2026-06-11T22:16:53.933

Link: CVE-2026-12014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T22:45:05Z

Weaknesses