Description
Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome’s Cast feature contains a flaw that insufficiently validates untrusted input before version 150.0.7871.47. A remote attacker who has already compromised the renderer process can serve a craftily constructed HTML page that triggers escalation of privileges on the host operating system. The vulnerability is an input‑validation weakness (CWE‑20) and is rated with a CVSS base score of 7.5, indicating moderate‑to‑high severity.

Affected Systems

All installations of Google Chrome with versions older than 150.0.7871.47 are impacted. The affected component is the Cast feature in the Chrome browser. Users running version 150.0.7871.47 or newer have the fix applied.

Risk and Exploitability

The EPSS score of less than 1 % suggests a low overall likelihood of exploitation. The CVSS base score is 7.5, indicating moderate‑to‑high severity. The vulnerability is not listed in the CISA KEV catalog, further implying limited current exploitation. Exploitation requires that the attacker already control the renderer process and deliver a malicious HTML page; based on the description, it is inferred that the likely attack vector is web‑based.

Generated by OpenCVE AI on July 21, 2026 at 15:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 150.0.7871.47 or later to obtain the fix
  • Enable automatic updates or install the latest stable release manually if automatic updating is disabled
  • If a prompt update is not feasible, disable the Cast feature via browser policy or chrome://flags to reduce the attack surface

Generated by OpenCVE AI on July 21, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Allows Privilege Escalation

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Insufficient Cast Input Validation in Chrome

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Insufficient Cast Input Validation in Chrome

Sun, 12 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Cast Input Validation in Google Chrome

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Cast Input Validation in Google Chrome

Fri, 10 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unvalidated Cast Input in Chrome

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unvalidated Cast Input in Chrome

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Enables Privilege Escalation

Tue, 07 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Enables Privilege Escalation

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome Cast Enables Privilege Escalation

Sat, 04 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome Cast Enables Privilege Escalation

Sat, 04 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Chrome Cast from Untrusted Input

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Chrome Cast from Untrusted Input

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Validation in Chrome Cast Component

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Validation in Chrome Cast Component

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Enables Privilege Escalation via Crafted HTML

Thu, 02 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Enables Privilege Escalation via Crafted HTML

Thu, 02 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Cast Input Validation Error Allows Privilege Escalation

Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chrome Cast Input Validation Error Allows Privilege Escalation

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:16.373Z

Reserved: 2026-06-29T23:11:45.197Z

Link: CVE-2026-14115

cve-icon Vulnrichment

Updated: 2026-07-01T14:22:47.155Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation