Sceawere

Vulnerability Detail

CVE-2026-79121UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chromecast Remote Code Execution Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
22h ago
Vendor
Google
Product
Chrome
Attack Type
Improper input validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-08-25T21:18:07.210Z",
  "pubdate": "2026-08-25T21:18:07.210Z",
  "executiveSummary": "This vulnerability involves improper input validation within the Chromecast component of Google Chrome, identified as a critical security flaw.\nThe vulnerability allows a remote attacker who has already compromised the renderer process to perform a sandbox escape, leading to arbitrary code execution.\nThe flaw affects Google Chrome versions prior to 152.0.7977.65.\nSuccessful exploitation poses a severe risk, as it permits an attacker to transition from a restricted renderer sandbox environment to executing malicious code on the host system.\nExploitation requires the attacker to successfully compromise the renderer process, typically achieved through a crafted HTML page, before leveraging the validation flaw to bypass security boundaries.\nGiven the 'Critical' severity rating, this represents a significant threat to system integrity and user data confidentiality, necessitating prompt application of security updates.",
  "technicalDetails": "The vulnerability originates from a deficiency in input validation logic within the Chromecast integration component of the Chromium browser architecture.\nThe attack flow begins when an attacker lures a user to a crafted HTML page designed to exploit a vulnerability in the renderer process, effectively gaining code execution within the browser's restricted sandbox environment.\nOnce the renderer process is compromised, the attacker leverages the improper input validation within the Chromecast sub-system to interact with privileged interfaces or IPC (Inter-Process Communication) channels that should remain inaccessible from the renderer.\nBy supplying maliciously crafted input that fails to undergo rigorous validation before being processed by the Chromecast component, the attacker triggers an out-of-bounds or unsafe memory operation.\nThis behavior facilitates a sandbox escape, allowing the attacker to elevate privileges from the restricted renderer context to the host process context.\nUpon successful escape, the attacker can execute arbitrary code on the underlying operating system with the privileges of the Chrome process.\nThe vulnerable component specifically resides within the Chromecast handling routines, which are susceptible to malformed data inputs when processing external communications or state transitions initiated from within the renderer.\nAffected versions include all Google Chrome releases prior to 152.0.7977.65.\nThe exploit does not require prior authentication from the victim, although it assumes the attacker has the ability to influence the renderer's state through web-based content.\nThe post-exploitation impact includes full system compromise, potential exfiltration of sensitive user data, installation of persistent malicious software, or lateral movement within the local network, as the sandbox security boundary has been effectively neutralized."
}
CVE-2026-79121: Chromecast Remote Code Execution Vulnerability (HIGH Severity, CVSS: 8.3) - Sceawere