Junglewise Threat Intelligence

CVE-2026-14045: Google Chrome improper input validation in Network

CVE-2026-14045 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its networking component could allow a remote attacker who has already partially compromised the browser to steal sensitive data from other websites. This could lead to the exposure of personal information or login sessions from sites the user is currently visiting.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Network component of Google Chrome. The flaw allows an attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin isolation boundaries. By utilizing a specially crafted HTML page, the attacker can leak data from different origins (cross-origin data). The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. It is rated as Low severity by Chromium.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats