Description
Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weakness arises from an inadequate check in the Chromecast implementation in Google Chrome. When an attacker has already compromised the renderer process, they can deliver a specially crafted HTML page that causes the browser to bypass navigation restrictions. The flaw permits enforcement of navigation limits to be overridden, potentially allowing the attacker to direct users to unintended destinations without their consent. This weakness aligns with CWE‑20, which deals with improper input validation or sanitization that allows an attacker to influence program behavior.

Affected Systems

This issue affects Google Chrome versions earlier than 150.0.7871.47 on any platform that includes the Chromecast component. The vulnerability exists in the Chromecast functionality of Chrome and applies to all builds released prior to the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% reflects a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already have control over the renderer process; once that condition is met, the attacker can use it to circumvent navigation restrictions but does not grant unrestricted access to the system.

Generated by OpenCVE AI on July 31, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later, as released in June 2026.
  • Enable renderer process isolation and sandboxing to reduce the likelihood of an attacker gaining initial renderer control.
  • Monitor for suspicious activity such as unexpected redirects or pop‑ups that may indicate compromised renderer behavior and investigate promptly.

Generated by OpenCVE AI on July 31, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer Process

Mon, 27 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer Process

Tue, 21 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Compromised Renderer Allows Navigation Bypass in Chrome's Chromecast

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Compromised Renderer Allows Navigation Bypass in Chrome's Chromecast

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Wed, 08 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chromecast in Chrome Bypass Navigation Restrictions via Compromised Renderer Process

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Chromecast in Chrome Bypass Navigation Restrictions via Compromised Renderer Process

Sun, 05 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer Process

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer Process

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer in Chrome

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer in Chrome

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Chromecast Renderer Enables Navigation Bypass After Compromise

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome Chromecast Renderer Enables Navigation Bypass After Compromise

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Thu, 02 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Restriction Bypass via Compromised Renderer

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Bypass via Compromised Renderer in Chrome

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chromecast Navigation Bypass via Compromised Renderer in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:04:06.646Z

Reserved: 2026-06-29T23:03:47.463Z

Link: CVE-2026-13900

cve-icon Vulnrichment

Updated: 2026-07-01T17:10:46.424Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation