CVE-2026-8005

MEDIUM

Google Chrome < 148.0.7778.96 - Same Origin Policy Bypass via Cast

Title source: llm
STIX 2.1

Description

Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 3.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
google/chrome < 148.0.7778.96
Google/Chrome 148.0.7778.96
Published May 06, 2026
Tracked Since May 07, 2026