Junglewise Threat Intelligence

CVE-2026-14004: Google Chrome cross-origin data leak in CSS

CVE-2026-14004 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's CSS implementation could allow a malicious website to leak data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially compromising the privacy of information from different origins. Google has released an update to address this issue in Chrome version 150.0.7871.47 and later.

Technical details

A cross-origin data leak vulnerability exists in Google Chrome's CSS engine due to an inappropriate implementation. By enticing a user to visit a malicious website, a remote attacker can leverage crafted HTML and CSS to bypass Same-Origin Policy (SOP) restrictions and extract information from other origins. This is classified by Chromium as a Medium severity issue. The vulnerability is resolved in Google Chrome version 150.0.7871.47 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats