Junglewise Threat Intelligence

CVE-2026-14023: Google Chrome Same Origin Policy bypass in SanitizerAPI

CVE-2026-14023 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Sanitizer API, a component used to safely handle and clean web content. An attacker could use a specially crafted website to bypass the browser's Same Origin Policy, which is a fundamental security boundary that prevents websites from interacting with data from other sites. This could potentially allow a malicious site to access sensitive information from other web pages the user has open.

Technical details

An improper input validation vulnerability (CWE-20) exists in the SanitizerAPI component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker via a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), potentially leading to unauthorized cross-origin data access. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. The attack requires user interaction to visit a malicious site but does not require special privileges.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: Google released a stable channel update addressing the issue.
  • 2026-06-30: disclosed: CVE-2026-14023 was published.

References

Related threats