Junglewise Threat Intelligence

CVE-2026-14096: Google Chrome for Android cross-origin data leak in Input

CVE-2026-14096 · Severity: info · CVSS 3.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used to access the internet. A vulnerability in the Android version of the browser could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information if a user visits a specially crafted web page.

Technical details

An inappropriate implementation in the Input component of Google Chrome on Android allowed a remote attacker to leak cross-origin data. The vulnerability requires the attacker to have already compromised the renderer process. By enticing a user to visit a crafted HTML page, the attacker can bypass Same-Origin Policy (SOP) protections to access data from other origins. This issue is fixed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats