Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | chromium-browser: Insufficient validation of untrusted input in Cast | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 07 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Validation in Chrome Cast Bypasses Same Origin Policy |
Thu, 07 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Linux Linux linux Kernel Microsoft Microsoft windows |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Linux Linux linux Kernel Microsoft Microsoft windows |
Thu, 07 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Validation in Chrome Cast Bypasses Same Origin Policy |
Wed, 06 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 06 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome |
|
| Vendors & Products |
Google
Google chrome |
Wed, 06 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low) | |
| Weaknesses | CWE-20 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published: 2026-05-06T18:13:09.985Z
Updated: 2026-05-06T21:47:50.648Z
Reserved: 2026-05-05T22:59:33.058Z
Link: CVE-2026-8005
Updated: 2026-05-06T21:20:48.474Z
Status : Analyzed
Published: 2026-05-06T19:16:51.477
Modified: 2026-05-07T13:54:02.197
Link: CVE-2026-8005