CVE-2026-10888: Critical Use after free in Cast Streaming
Chromium: CVE-2026-10888 Use after free in Cast Streaming
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome/Chromium Cast Streamingto a version that resolves this vulnerability.Fixed in 149.0.7827.53 - Compensating control
Limit network access to the local network segment so an attacker cannot send malicious network traffic to Cast Streaming (CVE-2026-10888).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-11669
- CVE-2026-8513
- CVE-2026-9979
- CVE-2026-10982
- CVE-2026-11693
- CVE-2026-11694
- CVE-2026-11660
- CVE-2026-11697
- CVE-2026-11692
- CVE-2026-11670
- CVE-2026-11646
- CVE-2026-11683
- CVE-2026-11689
- CVE-2026-9952
- CVE-2026-11651
- CVE-2026-10981
- CVE-2026-11682
- CVE-2026-11674
- CVE-2026-10988
- CVE-2026-11662
- CVE-2026-15901
- CVE-2026-9986
- CVE-2026-7357
- CVE-2026-9985
- CVE-2026-15765
- CVE-2026-13860
- CVE-2026-15133
- CVE-2026-15129
Frequently Asked Questions
What is the severity of CVE-2026-10888?
The severity of CVE-2026-10888 is high with a CVSS score of 8.8.
What is CVE-2026-10888 about?
CVE-2026-10888 is a use after free vulnerability in Cast Streaming found in Google Chrome.
Which software is affected by CVE-2026-10888?
CVE-2026-10888 affects Google Chrome and Microsoft Edge's Chromium-based version.
How do I fix CVE-2026-10888?
To fix CVE-2026-10888, update to the latest version of Google Chrome or Microsoft Edge.
What impact does CVE-2026-10888 have on users?
CVE-2026-10888 could allow an attacker to execute arbitrary code via the vulnerable Cast Streaming feature.