Use-after-free in Chromecast allows sandbox code execution
Use-after-free in Google Chrome's Chromecast component allows remote code execution inside the sandbox via a crafted HTML page. CVSS 9.6. Patched in Chrome 155.
- Vendor
- Product
- Chrome (Chromecast component, prior to 155.0.8059.39)
- CVSS
- 9.6
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-106382 is a use-after-free vulnerability in the Chromecast component of Google Chrome. An attacker serving a crafted HTML page can trigger the bug to execute arbitrary code inside the renderer sandbox.
Google discovered this vulnerability internally and patched it in Chrome 155.0.8059.39 (Windows, macOS, Linux), released October 7, 2026. No exploitation in the wild has been reported.
Update to Chrome 155.0.8059.39 or later. Enterprise teams using deferred update policies should prioritize this release given the CVSS 9.6 score and three other critical use-after-free bugs patched in the same update.
