Junglewise Threat Intelligence

CVE-2026-14082: Google Chrome race condition in Storage

CVE-2026-14082 · Severity: info · CVSS 3.7 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's storage component could allow a malicious website to access data from other websites you have visited. This occurs due to a timing issue when the browser handles data storage, potentially leading to the exposure of sensitive user information. Users should update to the latest version of Chrome to resolve this issue.

Technical details

A race condition (CWE-362) exists in the Storage component of Google Chrome. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit improper synchronization during concurrent execution to bypass cross-origin resource sharing (CORS) protections. This allows the attacker to read sensitive data from other origins that would otherwise be restricted. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats