Description
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Published: 2026-05-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome’s Cast functionality validated untrusted network input without sufficient checks, a CWE‑20 flaw, allowing an attacker on the same local network segment to bypass the browser’s same origin policy. This weakness means the policy that normally isolates web content could be circumvented, permitting a malicious source to interact with pages from a different origin in the victim’s browser context.

Affected Systems

The issue affects Chromium‑based Google Chrome desktop browsers earlier than version 148.0.7778.96. Any installation that includes the Cast component is impacted, regardless of operating system, as the vulnerability resides in the Cast network handling code.

Risk and Exploitability

The CVSS score is 4.3, indicating low to moderate severity. No EPSS data is provided, so the likelihood of exploitation remains undefined. The vulnerability requires a local attacker on the same network segment to send crafted network traffic that the Cast module processes; no internet‑wide exploitation is described. The flaw is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on May 7, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 148.0.7778.96 or later.
  • If an update cannot be applied immediately, disable the Cast feature via Chrome policies or settings to remove the vulnerable code path.
  • Reinforce network segmentation to prevent unauthorized devices from reaching the victim’s machine on the local segment.

Generated by OpenCVE AI on May 7, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Bypasses Same Origin Policy

Wed, 06 May 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 06 May 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:47:50.648Z

Reserved: 2026-05-05T22:59:33.058Z

Link: CVE-2026-8005

cve-icon Vulnrichment

Updated: 2026-05-06T21:20:48.474Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:51.477

Modified: 2026-05-07T13:54:02.197

Link: CVE-2026-8005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:15:17Z

Weaknesses