Description
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow (CWE-472) in the Chromecast component can be triggered by a crafted HTML page once the renderer process has been compromised. The flaw corrupts memory, giving the attacker the possibility of escaping the sandbox and potentially gaining higher privileges within the browser, which could lead to a loss of confidentiality, integrity or availability.

Affected Systems

All versions of Google Chrome running on any operating system before 150.0.7871.47 are affected. The CVE does not list specific operating systems, so the impact is limited to any system that runs the vulnerable Chrome build. Users who cannot immediately update should be aware that the vulnerability remains if Chromecast remains enabled.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity. The EPSS score is below 1% and it is not listed in the CISA KEV catalog, implying that active exploitation is currently unlikely. However, once the attacker gains control of the renderer process—a prerequisite for this exploit—they can use a crafted HTML page to trigger the integer overflow and escape the sandbox, elevating their privileges within the browser environment.

Generated by OpenCVE AI on July 31, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, which removes the vulnerable Chromecast component.
  • If an immediate update is not possible, disable Chromecast via Chrome’s settings, flags, or group policy to prevent the exploitation path.
  • Ensure that the system’s operating‑system security patches are current and that Chrome’s built‑in sandbox is enabled; strong OS‑level isolation limits damage if an integer overflow were to occur.

Generated by OpenCVE AI on July 31, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Potential Sandbox Escape

Sun, 26 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chromium Chromecast Integer Overflow Enables Sandbox Escape

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chromium Chromecast Integer Overflow Enables Sandbox Escape

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Potential Sandbox Escape in Google Chrome

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Potential Sandbox Escape in Google Chrome

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Leading to Sandbox Escape in Google Chrome

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Leading to Sandbox Escape in Google Chrome

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Potentially Enabling Sandbox Escape

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Potentially Enabling Sandbox Escape

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Tue, 07 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Sandbox Escape

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Sandbox Escape

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Sun, 05 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Allows Sandbox Escape in Chrome

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Sandbox Escape in Google Chrome

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Sandbox Escape in Google Chrome

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Thu, 02 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Browser Sandbox Escape

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Potential Sandbox Escape

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Potential Sandbox Escape

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:08.097Z

Reserved: 2026-06-29T23:03:21.105Z

Link: CVE-2026-13801

cve-icon Vulnrichment

Updated: 2026-07-01T15:30:45.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:16:54.833

Modified: 2026-07-02T05:16:30.217

Link: CVE-2026-13801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter