Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
References
| Link | Resource |
|---|---|
| https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html | Release Notes Vendor Advisory |
| https://issues.chromium.org/issues/513136593 | Permissions Required |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Jun 2026, 20:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apple macos
Linux Apple Linux linux Kernel Google chrome Microsoft windows Microsoft |
|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| References | () https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html - Release Notes, Vendor Advisory | |
| References | () https://issues.chromium.org/issues/513136593 - Permissions Required |
05 Jun 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
04 Jun 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 23:16
Updated : 2026-06-05 20:14
NVD link : CVE-2026-10890
Mitre link : CVE-2026-10890
CVE.ORG link : CVE-2026-10890
JSON object : View
Products Affected
- chrome
microsoft
- windows
apple
- macos
linux
- linux_kernel
CWE
CWE-416
Use After Free
