Description
Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow exists in the Chromecast component of Google Chrome versions earlier than 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to load a specially crafted HTML page that may provoke a sandbox escape, giving the attacker higher privileges within the browser process. The vulnerability does not guarantee control of the underlying operating system and requires an initial renderer-level compromise.

Affected Systems

All installations of Google Chrome on the stable desktop channel running a version earlier than 150.0.7871.47 are susceptible. The issue targets the Chromecast functionality built into the browser, affecting any user who has the Cast feature enabled on those legacy builds.

Risk and Exploitability

The CVSS score of 9.6 marks this flaw as critical, yet its EPSS score is below 1%, indicating a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an initial renderer compromise, followed by delivery of malicious HTML content. The overall risk depends on how exposed users are to renderer-level attacks and the use of the Cast feature.

Generated by OpenCVE AI on July 22, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to receive the heap overflow patch.
  • In enterprise environments, disable the Chromecast functionality through group policy or local settings to reduce attack surface.
  • Enforce an update policy that automatically installs the latest Chrome releases and blocks older, vulnerable versions from running.

Generated by OpenCVE AI on July 22, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 22 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow in Google Chrome Allows Potential Sandbox Escape

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enabling Sandbox Escape

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enabling Sandbox Escape

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Sat, 11 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Wed, 08 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Sandbox Escape

Tue, 07 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Heap buffer overflow in Chrome Chromecast enables sandbox escape

Mon, 06 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Heap buffer overflow in Chrome Chromecast enables sandbox escape

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enabling Sandbox Escape in Chrome

Sun, 05 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enabling Sandbox Escape in Chrome

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chromecast Component Heap Buffer Overflow Enables Remote Sandbox Escape

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chromecast Component Heap Buffer Overflow Enables Remote Sandbox Escape

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Overflow Enables Browser Sandbox Escape

Fri, 03 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Overflow Enables Browser Sandbox Escape

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chromium Chromecast Heap Buffer Overflow Enabling Sandbox Escape

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chromium Chromecast Heap Buffer Overflow Enabling Sandbox Escape

Thu, 02 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Remote Sandbox Escape

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Enables Remote Sandbox Escape

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Allowing Remote Code Execution

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chromecast Heap Buffer Overflow Allowing Remote Code Execution

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:12.479Z

Reserved: 2026-06-29T23:03:20.375Z

Link: CVE-2026-13798

cve-icon Vulnrichment

Updated: 2026-07-01T15:34:31.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T16:00:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow