PT-2026-38198 · Google · Google Chrome

Published

2026-05-05

·

Updated

2026-05-14

·

CVE-2026-8005

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 148.0.7778.96
Description Insufficient validation of untrusted input in Cast allows an attacker on the local network segment to bypass the same origin policy via malicious network traffic. The same origin policy is a critical security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin.
Recommendations Update to version 148.0.7778.96 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-8005
ECHO-B004-01D7-4766
OPENSUSE-SU-2026:10778-1

Affected Products

Google Chrome