Junglewise Threat Intelligence

CVE-2026-14049: Google Chrome inappropriate implementation in GPU

CVE-2026-14049 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser's graphics processing unit (GPU) component. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser could exploit this flaw to access sensitive information stored in the computer's memory. This could lead to the exposure of private data from other open tabs or browser processes.

Technical details

An information disclosure vulnerability exists in the GPU component of Google Chrome prior to version 150.0.7871.47. The flaw is characterized as an 'inappropriate implementation' that can be triggered by a remote attacker via a crafted HTML page. A successful exploit requires the attacker to have already compromised the renderer process (a sandbox escape or prior compromise precondition). Once achieved, the attacker can read potentially sensitive information from the process memory. This issue was addressed in the stable channel update to version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats