Heap Buffer Overflow in Chromecast on Google Chrome by Google
CVE-2026-9123

7.5HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-9123?

A heap buffer overflow vulnerability exists in Chromecast within Google Chrome prior to version 148.0.7778.179 across various platforms, including Android, Linux, and ChromeOS. A local attacker could exploit this flaw by sending specially crafted network traffic to execute arbitrary code within a sandboxed environment, leading to potential security breaches. This vulnerability underscores the importance of timely updates and rigorous security measures to protect users from unauthorized access and code execution risks associated with their devices.

Affected Version(s)

Chrome 148.0.7778.179

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.