Junglewise Threat Intelligence

CVE-2026-14061: Google Chrome information disclosure in Dawn

CVE-2026-14061 · Severity: info · CVSS 3.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted web page, potentially exposing private data to an attacker. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An information disclosure vulnerability exists in Dawn, the WebGPU implementation in Google Chrome, due to an inappropriate implementation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read potentially sensitive information from the browser's process memory. This issue affects Google Chrome versions prior to 150.0.7871.47 and has been addressed in the stable channel update.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats