Junglewise Threat Intelligence

CVE-2026-14041: Google Chrome privilege escalation in Serial API

CVE-2026-14041 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Serial API component could allow a malicious website to gain unauthorized privileges on a user's system. This could potentially lead to unauthorized access to hardware or sensitive data if a user visits a specially crafted webpage.

Technical details

A privilege escalation vulnerability exists in the Serial API component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. The flaw allows the attacker to bypass intended security restrictions and escalate privileges within the browser context. Google has addressed this issue in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats