Description
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow bug in the Chromecast component of Google Chrome before version 150.0.7871.47 can be triggered by a crafted HTML page. The overflow allows a remote attacker who has already compromised a renderer process to escape the renderer sandbox and execute code with higher privileges on the host system. This vulnerability is classified as CWE‑472 and carries a high severity rating.

Affected Systems

Google Chrome, all users running any Chrome version earlier than 150.0.7871.47, on any platform that includes the Chromecast feature.

Risk and Exploitability

The vulnerability requires that an attacker already control a renderer process, which typically means they have previously compromised the browser process or exploited another flaw. Once that prerequisite is satisfied, delivery of a specially formatted web page can trigger the integer overflow and cause the renderer to break out of its sandbox. Exploit evidence is not yet publicly confirmed and the EPSS score is currently unavailable, but the high CVSS severity and lack of a CISA KEV listing suggest that the risk to exposed systems is moderate to high for environments that accept arbitrary web content.

Generated by OpenCVE AI on July 1, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, which contains the patched Chromecast code.
  • Disable the Chromecast feature in Chrome by turning off "Enable media router" in "chrome://flags" to eliminate the attack vector if a patch cannot be applied immediately.
  • Use enterprise policy or user configuration to restrict or block casting, ensuring that Chromecast APIs are not exposed on the local network.

Generated by OpenCVE AI on July 1, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Sandbox Escape in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:37:36.183Z

Reserved: 2026-06-29T23:03:19.887Z

Link: CVE-2026-13796

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:00:14Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter