Junglewise Threat Intelligence

CVE-2026-14098: Google Chrome cross-origin data leak in CSS

CVE-2026-14098 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its CSS implementation. This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. While rated as low severity, it represents a potential risk to user privacy and data isolation.

Technical details

A vulnerability exists in the CSS implementation of Google Chrome due to an inappropriate implementation that fails to strictly enforce cross-origin boundaries. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to leak sensitive data from a different origin (cross-origin data leakage). The issue is addressed in Chrome version 150.0.7871.47 and later. The vulnerability is categorized by Chromium as Low severity.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats