Impact
Insufficient validation of untrusted input in Chrome’s Chromecast component permits a local attacker to craft malicious network traffic that targets the Chromecast interface. When processed, this traffic can cause the browser’s sandbox to be bypassed, allowing execution of higher‑privilege code within the system. The weakness is an input validation flaw classified as CWE‑20 and is rated as High severity by Chromium.
Affected Systems
All Windows, macOS, and Linux installations of Google Chrome running any version older than 150.0.7871.182, as those releases include the vulnerable Chromecast handling code.
Risk and Exploitability
Exploitation requires an attacker who can generate or inject malicious network packets addressed to the Chromecast service from a local network. Because the attack vector is local and tied specifically to Chromecast traffic, the exposure is confined to environments where Chromecast functionality is enabled and reachable. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.3 indicates severe potential impact if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA