High severity8.8NVD Advisory· Published Jun 4, 2026· Updated Jun 5, 2026
CVE-2026-10890
CVE-2026-10890
Description
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
Affected products
5- osv-coords3 versionspkg:apk/chainguard/chromiumpkg:apk/wolfi/chromiumpkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
< 149.0.7827.53-r0+ 2 more
- (no CPE)range: < 149.0.7827.53-r0
- (no CPE)range: < 149.0.7827.53-r0
- (no CPE)range: < 149.0.7827.53-2.1
Patches
Vulnerability mechanics
References
2- chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.htmlnvdRelease NotesVendor Advisory
- issues.chromium.org/issues/513136593nvdPermissions Required
News mentions
0No linked articles in our index yet.