Junglewise Threat Intelligence

CVE-2026-14085: Google Chrome side-channel information leakage in CSS

CVE-2026-14085 · Severity: info · CVSS 3.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles CSS (website styling) could allow a malicious website to secretly extract information from other websites you have open. This type of 'side-channel' attack could lead to the unauthorized disclosure of sensitive user data across different web domains.

Technical details

A side-channel information leakage vulnerability exists in the CSS implementation of Google Chrome. The flaw (CWE-1300) allows a remote attacker to bypass cross-origin isolation boundaries. By enticing a user to visit a specially crafted HTML page, an attacker can use CSS-based timing or state-based side channels to infer and leak data from a different origin. This vulnerability was addressed in Chrome version 150.0.7871.47. Access to specific bug details is currently restricted by the Chromium team to allow users time to update.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: Google released stable channel update 150.0.7871.47 for Desktop
  • 2026-06-30: disclosed: CVE-2026-14085 published

References

Related threats