Junglewise Threat Intelligence

CVE-2026-14065: Google Chrome improper input validation in PageInfo

CVE-2026-14065 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the PageInfo component could allow an attacker who has already partially compromised the browser's rendering process to bypass security restrictions that normally limit where a user can navigate. This could potentially be used to facilitate further attacks or access restricted content via a specially crafted web page.

Technical details

An improper input validation vulnerability (CWE-20) exists in the PageInfo component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by utilizing a specially crafted HTML page. This is a post-compromise primitive that weakens the browser's sandbox or site isolation boundaries. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats