Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
https://issues.chromium.org/issues/496298665
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html