Description
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow (CWE‑472) in the Chromecast component of Google Chrome can be triggered by a crafted HTML page once the renderer process has already been compromised. The overflow corrupts memory, potentially breaking the browser sandbox and allowing the attacker to acquire higher privileges within the browser, indicating that successful exploitation significant loss of confidentiality, integrity, or availability.

Affected Systems

Google Chrome versions prior to 150.0.7871.47 are affected. The specific operating systems that run these versions are not listed in the CVE data, so the earlier claim that all supported operating systems are affected is inferred rather than explicitly documented. Any user running a Chrome release before that version, or any distribution that ships with a Chromium build older than the patched version, is exposed unless the Chromecast component has already been patched or disabled.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity, while the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first compromise the renderer process; once achieved, a malicious HTML page can trigger the integer overflow to escape the sandbox. Because this flaw exists only in unpatched Chrome releases, the risk is elevated for systems remaining on older versions, but the low EPSS indicates that active exploitation is currently unlikely.

Generated by OpenCVE AI on July 21, 2026 at 17:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to remove the vulnerable Chromecast code.
  • If an update is not immediately possible, disable the Chromecast feature through Chrome settings, flags, or group policy to eliminate the risk.
  • Apply all latest operating system security patches and verify that Chrome’s built‑in sandbox is enabled; enforcing strong OS‑level isolation limits damage if an integer overflow were to occur.

Generated by OpenCVE AI on July 21, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chromium Chromecast Integer Overflow Enables Sandbox Escape

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Potential Sandbox Escape in Google Chrome

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Potential Sandbox Escape in Google Chrome

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Leading to Sandbox Escape in Google Chrome

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Leading to Sandbox Escape in Google Chrome

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Potentially Enabling Sandbox Escape

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Potentially Enabling Sandbox Escape

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Tue, 07 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Sandbox Escape

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Sandbox Escape

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Sun, 05 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Sandbox Escape in Google Chrome

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Sandbox Escape in Google Chrome

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Thu, 02 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Potential Sandbox Escape

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Potential Sandbox Escape

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:08.097Z

Reserved: 2026-06-29T23:03:21.105Z

Link: CVE-2026-13801

cve-icon Vulnrichment

Updated: 2026-07-01T15:30:45.731Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:45:02Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter