CVE-2026-13940
published 2026-06-30CVE-2026-13940: Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information…
PriorityP429medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.21%
11.7th percentile
Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13938
vendor_chrome·2026-06-30·CVSS 3.1
CVE-2026-13938 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-13938
Stable Channel Update for Desktop
CVE-2026-13938: Integer overflow in Fonts. Reported by Google on 2026-05-14 [N/A][ 513149760 ] Medium CVE-2026-13939: Insufficient validation of untrusted input in WebShare
Reported by Google on 2026-05-14 [N/A][ 513158425 ] Medium CVE-2026-13940: Uninitialized Use in Cast
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2026-13940
vendor_chrome·2026-06-30
CVE-2026-13940 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-13940
Stable Channel Update for Desktop
CVE-2026-13940: Uninitialized Use in Cast. Reported by Google on 2026-05-14 [N/A][ 513183855 ] Medium CVE-2026-13941: Inappropriate implementation in SiteSettings
Reported by Google on 2026-05-14 [N/A][ 513186670 ] Medium CVE-2026-13942: Insufficient validation of untrusted input in Video Capture
Severity: medium
GHSA
Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network
ghsa_unreviewed·2026-07-01
CVE-2026-13940 [MEDIUM] CWE-457 Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network
Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published