Junglewise Threat Intelligence

CVE-2026-14022: Google Chrome improper input validation in Network

CVE-2026-14022 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's networking component could allow a malicious website to access data from other websites. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the exposure of sensitive user information across different web domains. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Network component of Google Chrome prior to version 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to bypass cross-origin isolation boundaries. By enticing a user to visit a specially crafted HTML page, the attacker can leak sensitive data from other origins. This is classified by Chromium as Medium severity. A fix is available in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats