Junglewise Threat Intelligence

CVE-2026-14055: Google Chrome sandbox escape in Device Trust on Windows

CVE-2026-14055 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the Device Trust component on Windows could allow a remote attacker who has already partially compromised the browser to escape its security sandbox. If successful, this could allow the attacker to gain broader access to the underlying Windows operating system, potentially leading to unauthorized data access or system control.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Device Trust component of Google Chrome for Windows. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process (e.g., via a separate exploit). By enticing a user to visit a specially crafted HTML page, the attacker can leverage the insufficient validation to break out of the browser's restricted environment. This issue was fixed in version 150.0.7871.47. Google characterizes the severity of this specific sandbox escape vector as Low.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats