Junglewise Threat Intelligence

CVE-2026-14116: Google Chrome improper input validation in DevTools

CVE-2026-14116 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's DevTools, a set of web developer tools built directly into the browser, contained a vulnerability that could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard actions. While the risk is considered low, successful exploitation could lead to the unauthorized disclosure of sensitive information from other open browser tabs or services.

Technical details

A vulnerability exists in the DevTools component of Google Chrome due to improper input validation (CWE-20). A remote attacker can exploit this by hosting a malicious HTML page and inducing a user to perform specific UI gestures. This interaction allows the attacker to bypass cross-origin isolation and leak data from different origins. The vulnerability is classified by Chromium as Low severity and was addressed in version 150.0.7871.47. Access to full bug details is currently restricted to prevent further exploitation while users update.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats