CVE-2026-15902

Google · Chrome

A use-after-free vulnerability in the Cast component of Google Chrome allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Executive summary

A high-severity use-after-free vulnerability in the Google Chrome Cast component permits remote code execution, requiring immediate browser updates to maintain endpoint security.

Vulnerability

This is a use-after-free vulnerability within the Cast functionality of the browser. An unauthenticated attacker can exploit this by directing a user to a malicious HTML page, which triggers the flaw and allows for arbitrary code execution within the browser's sandbox environment.

Business impact

Despite the browser's internal sandbox, the ability to execute arbitrary code remains a high-risk scenario. A CVSS score of 9.6 highlights the potential for serious security breaches, including data theft or unauthorized system interaction. Maintaining unpatched versions of Chrome exposes the organization to preventable attacks that leverage common browsing habits.

Remediation

Immediate Action: Update all installations of Google Chrome to version 150.0.7871.128 or newer.

Proactive Monitoring: Review security logs for suspicious browser process activity or unexpected crashes that may indicate an exploitation attempt.

Compensating Controls: Utilize a modern Web Application Firewall or endpoint security agent that can detect and mitigate common browser-based exploit payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The combination of the high CVSS score and the nature of the Cast component makes this a priority update. Security teams must ensure that the latest stable release of Chrome is deployed to all corporate assets to mitigate the risk of arbitrary code execution.