Junglewise Threat Intelligence

CVE-2026-14059: Google Chrome cross-origin data leak in Related-Website-Sets

CVE-2026-14059 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in how it handles groups of related websites. A remote attacker could use a specially designed web page to bypass security boundaries and access data from other websites. This could lead to the unauthorized exposure of user information across different web domains.

Technical details

A vulnerability exists in Google Chrome's Related-Website-Sets (formerly First-Party Sets) mechanism due to insufficient policy enforcement. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a maliciously crafted HTML page. Successful exploitation enables the attacker to leak sensitive data across origins that should otherwise be restricted. The issue is addressed in Google Chrome version 150.0.7871.47 and later. Google has classified this as a Low severity security issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats