Junglewise Threat Intelligence

CVE-2026-14058: Google Chrome CSP bypass in Parser

CVE-2026-14058 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its HTML parsing component. This vulnerability could allow a malicious website to bypass Content Security Policy (CSP) protections, which are designed to prevent unauthorized scripts from running. If exploited, an attacker could potentially execute unauthorized actions or access data on websites that the user is visiting.

Technical details

A vulnerability classified as insufficient policy enforcement existed in the HTML Parser of Google Chrome. The flaw allowed a remote attacker to bypass Content Security Policy (CSP) mechanisms by enticing a user to visit a specially crafted HTML page. CSP is a critical security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection attacks. By bypassing these restrictions, an attacker could potentially execute unauthorized scripts in the context of the affected site. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats