Junglewise Threat Intelligence

CVE-2026-14062: Google Chrome on ChromeOS Information Disclosure in Views

CVE-2026-14062 · Severity: info · CVSS 2.5 · Published 2026-06-30

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A vulnerability in the Views component of Google Chrome on ChromeOS could allow a malicious extension to access sensitive information. To exploit this, an attacker must trick a user into installing a specially crafted Chrome extension. Once installed, the extension could read data from the browser's process memory, potentially exposing private user information.

Technical details

An inappropriate implementation in the Views component of Google Chrome on ChromeOS allowed for information disclosure. The vulnerability is triggered when a user installs and executes a malicious, specially crafted Chrome Extension. An attacker can leverage this flaw to read sensitive information from the browser's process memory. This issue was addressed in ChromeOS version 150.0.7871.47. The vulnerability is classified by Chromium as Low severity.

Affected products

  • Google ChromeOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats