Junglewise Threat Intelligence

CVE-2026-14105: Google Chrome Same Origin Policy bypass in Speech

CVE-2026-14105 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its Speech component. A remote attacker could use a specially crafted website to bypass security boundaries that normally prevent different websites from accessing each other's data. While rated as low severity, this could potentially allow a malicious site to interact with or access information from other open web pages.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the Speech component of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP), which is a fundamental security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. The attack vector involves a victim visiting a malicious, specially crafted HTML page. Successful exploitation could allow the attacker to perform unauthorized cross-origin actions. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD publication date
  • 2026-06-30: patched: Chrome Stable Channel Update released

References

Related threats