Junglewise Threat Intelligence

CVE-2026-14120: Google Chrome sandbox escape in DevTools

CVE-2026-14120 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a security flaw in its DevTools component, which is a set of web developer tools built directly into the browser. If an attacker has already compromised the browser's content rendering process, they could use this flaw to break out of the security sandbox that normally isolates the browser from the rest of the computer. This could potentially allow the attacker to gain broader access to the underlying operating system.

Technical details

This vulnerability is classified as an inappropriate implementation within the DevTools component of Google Chrome. The flaw requires a multi-stage attack: a remote attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, the attacker can leverage this DevTools flaw via a specially crafted HTML page to achieve a sandbox escape. A successful exploit allows the attacker to bypass the security boundaries intended to restrict the browser's access to the host operating system. The issue is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats