Description
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Published: 2026-05-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome’s Cast functionality validated untrusted network input without sufficient checks, a CWE‑20 flaw, and a CWE‑346 flaw. This combination allowed an attacker on the same local network segment to bypass the browser’s same origin policy. The weakness means the policy that normally isolates web content could be circumvented, permitting a malicious source to interact with pages from a different origin in the victim’s browser context.

Affected Systems

The issue affects Chromium‑based Google Chrome desktop browsers earlier than version 148.0.7778.96. Any installation that includes the Cast component is impacted, regardless of operating system, as the vulnerability resides in the Cast network handling code.

Risk and Exploitability

The CVSS score is 4.3, indicating low to moderate severity. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability stems from CWE‑20 input validation and CWE‑346 code injection weaknesses, requiring a local attacker on the same network segment to send crafted network traffic that the Cast module processes; no internet‑wide exploitation is described. The flaw is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on May 9, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 148.0.7778.96 or later.
  • If an update cannot be applied immediately, disable the Cast feature via Chrome policies or settings to remove the vulnerable code path.
  • Reinforce network segmentation to prevent unauthorized devices from reaching the victim’s machine on the local segment.

Generated by OpenCVE AI on May 9, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Sat, 09 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Insufficient validation of untrusted input in Cast
Weaknesses CWE-346
References
Metrics threat_severity

None

threat_severity

Low


Thu, 07 May 2026 16:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Bypasses Same Origin Policy

Thu, 07 May 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Cast Bypasses Same Origin Policy

Wed, 06 May 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 06 May 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:47:50.648Z

Reserved: 2026-05-05T22:59:33.058Z

Link: CVE-2026-8005

cve-icon Vulnrichment

Updated: 2026-05-06T21:20:48.474Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:51.477

Modified: 2026-05-07T13:54:02.197

Link: CVE-2026-8005

cve-icon Redhat

Severity : Low

Publid Date: 2026-05-05T00:00:00Z

Links: CVE-2026-8005 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-09T03:45:03Z