Description
Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An integer overflow was discovered in Chromecast components of Google Chrome versions prior to 152.0.7977.65. The flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that triggers the overflow, potentially enabling execution of arbitrary code outside the renderer sandbox. This flaw maps to CWE‑190 and can compromise the confidentiality, integrity, and availability of the host system if exploited.

Affected Systems

Google Chrome on desktop devices running version numbers below 152.0.7977.65, with Chromecast functionality enabled. The vulnerability affects all installations of Chrome that include the Chromecast rendering libraries for Windows, macOS, and Linux.

Risk and Exploitability

While the flagged severity in Chromium is labeled High, the CVSS score of 8.3 confirms a high level of risk. Exploitation requires a prior compromise of the renderer process, limiting practical risk to scenarios where an attacker can deliver malicious content that subverts the sandbox. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, but prompt update or restricted use of Chromecast is recommended.

Generated by OpenCVE AI on August 26, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later.
  • If upgrading immediately is not possible, disable or restrict Chromecast functionality to prevent the renderer from loading malicious content.
  • Continuously monitor Chrome security advisories for further patches or additional mitigations.

Generated by OpenCVE AI on August 26, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Code Execution Outside Sandbox

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chromecast Enables Code Execution Outside Sandbox

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:11.241Z

Reserved: 2026-08-25T06:13:24.194Z

Link: CVE-2026-79292

cve-icon Vulnrichment

Updated: 2026-08-26T16:32:52.969Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:23.417

Modified: 2026-08-27T04:17:59.697

Link: CVE-2026-79292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound