<Vulnerability name="CVE-2026-10890">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-02T00:00:00</PublicDate>
    <Bugzilla id="2485112" url="https://bugzilla.redhat.com/show_bug.cgi?id=2485112" xml:lang="en:us">
chromium-browser: Use after free in Cast
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-825</CWE>
    <Details xml:lang="en:us" source="Mitre">
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
An use after free flaw was found in the Cast component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=513136593
    </Details>
    <Statement xml:lang="en:us">
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10890
https://nvd.nist.gov/vuln/detail/CVE-2026-10890
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html
https://issues.chromium.org/issues/513136593
    </References>
</Vulnerability>