Junglewise Threat Intelligence

CVE-2026-14095: Google Chrome sandbox escape via insufficient policy enforcement

CVE-2026-14095 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's policy enforcement could allow a malicious website to bypass security restrictions if the browser's internal rendering process has already been compromised. This could lead to a 'sandbox escape,' potentially allowing an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's normal security boundaries.

Technical details

An insufficient policy enforcement vulnerability exists in the Browser component of Google Chrome. The flaw (CWE-20) allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this lack of enforcement to escape the browser's security sandbox. This vulnerability is addressed in Chrome version 150.0.7871.47 and later. Google classifies this as a 'Low' severity issue within the Chromium security framework.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats