Junglewise Threat Intelligence

CVE-2026-14071: Google Chrome side-channel information leakage in WebAudio

CVE-2026-14071 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, was found to have a security flaw in its WebAudio component. This vulnerability could allow a malicious website to bypass security boundaries and potentially access data from other websites you have open. While the risk is considered low, it could lead to the unauthorized leakage of sensitive information across different web origins.

Technical details

A side-channel information leakage vulnerability (CWE-1300) exists in the WebAudio component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. An attacker could exploit this by enticing a user to visit a specially crafted HTML page. The vulnerability is mitigated in version 150.0.7871.47 and later. Chromium developers have classified this as a Low severity issue.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published advisory
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats