CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
Chromium: CVE-2026-16414 Insufficient validation of untrusted input in Chromecast
Other sources
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.7871.181 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.96 - Upgrade
Upgrade
Google Chrome / Chromium (Chromecast)to a version that resolves this vulnerability.Fixed in 150.0.7871.182 - Compensating control
If affected devices are using Chromecast, limit/segment the network paths that Chromecast can receive traffic from (e.g., restrict inbound traffic to only trusted networks/devices) to reduce exposure to malicious network traffic that could trigger sandbox escape.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-16414?
The severity of CVE-2026-16414 is classified as High.
What causes CVE-2026-16414?
CVE-2026-16414 is caused by insufficient validation of untrusted input in Chromecast within Google Chrome.
How do I fix CVE-2026-16414?
To fix CVE-2026-16414, users should update Google Chrome to version 150.0.7871.182 or later.
Who is affected by CVE-2026-16414?
Users of Google Chrome prior to version 150.0.7871.182 are affected by CVE-2026-16414.
What can an attacker potentially do with CVE-2026-16414?
An attacker could potentially perform a sandbox escape via malicious network traffic due to CVE-2026-16414.