Sceawere
Vulnerability Detail
CVE-2026-79121UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Chromecast Remote Code Execution Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.3
- Creation Date
- 22h ago
- Vendor
- Product
- Chrome
- Attack Type
- Improper input validation
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.3",
"pubDate": "2026-08-25T21:18:07.210Z",
"pubdate": "2026-08-25T21:18:07.210Z",
"executiveSummary": "This vulnerability involves improper input validation within the Chromecast component of Google Chrome, identified as a critical security flaw.\nThe vulnerability allows a remote attacker who has already compromised the renderer process to perform a sandbox escape, leading to arbitrary code execution.\nThe flaw affects Google Chrome versions prior to 152.0.7977.65.\nSuccessful exploitation poses a severe risk, as it permits an attacker to transition from a restricted renderer sandbox environment to executing malicious code on the host system.\nExploitation requires the attacker to successfully compromise the renderer process, typically achieved through a crafted HTML page, before leveraging the validation flaw to bypass security boundaries.\nGiven the 'Critical' severity rating, this represents a significant threat to system integrity and user data confidentiality, necessitating prompt application of security updates.",
"technicalDetails": "The vulnerability originates from a deficiency in input validation logic within the Chromecast integration component of the Chromium browser architecture.\nThe attack flow begins when an attacker lures a user to a crafted HTML page designed to exploit a vulnerability in the renderer process, effectively gaining code execution within the browser's restricted sandbox environment.\nOnce the renderer process is compromised, the attacker leverages the improper input validation within the Chromecast sub-system to interact with privileged interfaces or IPC (Inter-Process Communication) channels that should remain inaccessible from the renderer.\nBy supplying maliciously crafted input that fails to undergo rigorous validation before being processed by the Chromecast component, the attacker triggers an out-of-bounds or unsafe memory operation.\nThis behavior facilitates a sandbox escape, allowing the attacker to elevate privileges from the restricted renderer context to the host process context.\nUpon successful escape, the attacker can execute arbitrary code on the underlying operating system with the privileges of the Chrome process.\nThe vulnerable component specifically resides within the Chromecast handling routines, which are susceptible to malformed data inputs when processing external communications or state transitions initiated from within the renderer.\nAffected versions include all Google Chrome releases prior to 152.0.7977.65.\nThe exploit does not require prior authentication from the victim, although it assumes the attacker has the ability to influence the renderer's state through web-based content.\nThe post-exploitation impact includes full system compromise, potential exfiltration of sensitive user data, installation of persistent malicious software, or lateral movement within the local network, as the sandbox security boundary has been effectively neutralized."
}