Junglewise Threat Intelligence

CVE-2026-14039: Google Chrome SOP bypass in GetUserMedia

CVE-2026-14039 · Severity: info · CVSS 3.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's media handling component could allow a malicious website to bypass standard security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially access information from other websites that should normally be protected. This issue is rated as low severity and has been addressed in the latest browser updates.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the GetUserMedia component of Google Chrome. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by utilizing a specially crafted HTML page. SOP is a fundamental security mechanism that prevents scripts on one origin from accessing data on another origin; bypassing it can lead to unauthorized information disclosure. The attack requires user interaction, specifically enticing a victim to visit a malicious URL. This issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats