Junglewise Threat Intelligence

CVE-2026-14090: Google ChromeOS out of bounds read in CameraCapture

CVE-2026-14090 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A vulnerability exists in the CameraCapture component of Google Chrome on ChromeOS. This flaw could allow a malicious website to read sensitive information from the device's memory that it should not have access to. While the risk is considered low, it could potentially lead to the exposure of private data if a user visits a specially crafted webpage.

Technical details

An out-of-bounds (OOB) read vulnerability (CWE-125) exists in the CameraCapture component of Google Chrome on ChromeOS. The issue stems from insufficient validation of untrusted input, which can be triggered when a user visits a maliciously crafted HTML page. A remote attacker can exploit this to perform an unauthorized memory read, potentially leaking sensitive information from the browser process. The vulnerability is fixed in ChromeOS version 150.0.7871.47 and later. Chromium developers have assigned this a 'Low' severity rating.

Affected products

  • Google ChromeOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats