Junglewise Threat Intelligence

CVE-2026-14056: Google Chrome improper input validation in Media

CVE-2026-14056 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser handles video files could allow a remote attacker who has already partially compromised the browser's rendering process to bypass security restrictions. This could potentially allow the attacker to escape the browser's 'sandbox'—a security layer designed to prevent malicious websites from accessing the rest of the computer—leading to broader access to the user's system.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within a compromised renderer process. The attack is triggered by processing a specially crafted video file. This vulnerability is rated as Low severity by Chromium because it requires a pre-existing compromise of the renderer process as a prerequisite. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats