Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-106382

Use-after-free in Chromecast allows sandbox code execution

Use-after-free in Google Chrome's Chromecast component allows remote code execution inside the sandbox via a crafted HTML page. CVSS 9.6. Patched in Chrome 155.

Vendor
Google
Product
Chrome (Chromecast component, prior to 155.0.8059.39)
CVSS
9.6
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-106382 is a use-after-free vulnerability in the Chromecast component of Google Chrome. An attacker serving a crafted HTML page can trigger the bug to execute arbitrary code inside the renderer sandbox.

Google discovered this vulnerability internally and patched it in Chrome 155.0.8059.39 (Windows, macOS, Linux), released October 7, 2026. No exploitation in the wild has been reported.

Update to Chrome 155.0.8059.39 or later. Enterprise teams using deferred update policies should prioritize this release given the CVSS 9.6 score and three other critical use-after-free bugs patched in the same update.