Junglewise Threat Intelligence

CVE-2026-14011: Google Chrome out of bounds read in SurfaceCapture

CVE-2026-14011 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its SurfaceCapture component could allow a malicious website to read sensitive information from the browser's memory. This could potentially lead to the exposure of private data or help an attacker bypass security protections.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the SurfaceCapture component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an unauthorized memory read. This could lead to information disclosure or be used as a primitive in a multi-stage exploit to bypass memory protections like ASLR. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats