Junglewise Threat Intelligence

CVE-2026-14038: Google Chrome improper input validation in New Tab Page

CVE-2026-14038 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's New Tab Page could allow a remote attacker to bypass security restrictions. If an attacker has already compromised a part of the browser, they could use this flaw to escape the 'sandbox'—a security layer designed to keep malicious code from reaching the rest of the computer. This could lead to unauthorized access to the user's system or data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the New Tab Page component of Google Chrome. A remote attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page. Successful exploitation could allow the attacker to perform a sandbox escape, potentially gaining broader access to the underlying operating system. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats