Description
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow condition in the Chromecast module of Google Chrome allows a local attacker to cause memory corruption when the browser processes crafted Chromecast traffic, leading to arbitrary code execution in the context of the user running Chrome. The weakness is a classic bounds‑checking failure (CWE-122) that can be triggered by malicious network packets.

Affected Systems

The vulnerability applies to all releases of Google Chrome for Windows, macOS, Linux, and other supported platforms that are older than version 150.0.7871.47. Deploying the Chrome installer shipped for those platforms after the June 2026 stable channel update implicitly fixes the flaw.

Risk and Exploitability

The vulnerability carries a CVSS base score of 8.8, indicating a high impact, yet the EPSS score is below 1 % and it is not catalogued in CISA KEV, suggesting limited or no active exploitation. The attack vector is local; an attacker must be able to transmit crafted Chromecast packets to a running Chrome instance on the target workstation. Successful exploitation results in arbitrary code execution limited to the user's privileges, which could be leveraged for further actions on the host if privileged processes run under that user.

Generated by OpenCVE AI on July 21, 2026 at 16:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to resolve the integer overflow issue.
  • If immediate upgrade is impossible, disable the Chromecast feature in Chrome settings to prevent the vulnerable code from executing.
  • Consider monitoring Chrome or network traffic for unexpected Chromecast activity to detect anomalous behavior early.

Generated by OpenCVE AI on July 21, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Arbitrary Code Execution

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Arbitrary Code Execution

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chrome Chromecast Enables Arbitrary Code Execution

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chrome Chromecast Enables Arbitrary Code Execution

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Local Arbitrary Code Execution

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enabling Local Arbitrary Code Execution

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Code Execution

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Code Execution

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chromecast Allows Arbitrary Code Execution

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chromecast Allows Arbitrary Code Execution

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Arbitrary Code Execution

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Chromecast Integer Overflow Enables Local Arbitrary Code Execution

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chromecast component allows local code execution

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chromecast component allows local code execution

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Component Enabling Local Code Execution

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Component Enabling Local Code Execution

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Chromecast Component Enables Local Arbitrary Code Execution

Thu, 02 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Chromecast Component Enables Local Arbitrary Code Execution

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chromecast Enables Arbitrary Code Execution

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Integer Overflow in Chromecast Enables Arbitrary Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Component Leading to Local Code Execution

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Component Leading to Local Code Execution

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:25.780Z

Reserved: 2026-06-29T23:03:41.808Z

Link: CVE-2026-13884

cve-icon Vulnrichment

Updated: 2026-07-01T13:11:17.192Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:00:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow