Junglewise Threat Intelligence

CVE-2026-14000: Google Chrome UXSS in XML implementation

CVE-2026-14000 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles XML data could allow a malicious website to run unauthorized scripts or display fake content on other websites you have open. This type of attack, known as Universal Cross-Site Scripting (UXSS), can lead to the theft of sensitive information like login session cookies or personal data from other web services.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's XML implementation. The flaw is categorized as an 'inappropriate implementation' that fails to properly isolate script execution environments when processing XML content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and inject arbitrary scripts or HTML into any web page or origin, potentially leading to full account takeover or data exfiltration across different domains. The issue is resolved in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats