Junglewise Threat Intelligence

CVE-2026-14017: Google Chrome sandbox escape in Navigation

CVE-2026-14017 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in the Google Chrome web browser could allow a malicious website to bypass security boundaries. If an attacker has already partially compromised the browser's internal processes, they could use a specially crafted webpage to escape the 'sandbox'—a security mechanism designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the underlying operating system or user data.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists within the Navigation component of Google Chrome. The flaw allows a remote attacker to perform a sandbox escape, provided they have already achieved code execution within a compromised renderer process. By enticing a user to visit a malicious HTML page, the attacker can exploit this navigation logic error to break out of the process isolation. This vulnerability was addressed in Chrome version 150.0.7871.47 for Windows, Mac, and Linux. Google has assigned this a 'Medium' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats