Junglewise Threat Intelligence

CVE-2026-14118: Google Chrome insufficient data validation in DevTools

CVE-2026-14118 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's DevTools, a set of web developer tools built directly into the browser, contained a vulnerability that could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. This could lead to the unauthorized exposure of sensitive information across different web domains.

Technical details

A vulnerability exists in Google Chrome's DevTools component due to insufficient data validation. A remote attacker can exploit this by hosting a malicious HTML page and tricking a user into performing specific UI gestures. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from other origins. The vulnerability is addressed in Chrome version 150.0.7871.47 and later. This issue is categorized by Chromium as Low severity.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats