Junglewise Threat Intelligence

CVE-2026-14124: Google Chrome privilege escalation in CredentialProvider

CVE-2026-14124 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome Credential Provider for Windows could allow a local user to gain elevated system privileges. The Credential Provider is a component that handles user authentication and sign-in processes on Windows devices. By using a specially crafted file, an attacker who already has basic access to a machine could bypass security controls to perform actions with higher-level administrative permissions, potentially compromising the entire operating system.

Technical details

A privilege escalation vulnerability exists in the Google Chrome CredentialProvider for Windows due to an inappropriate implementation of file handling or validation logic. A local attacker with unprivileged access can exploit this by placing or manipulating a malicious file that the CredentialProvider interacts with during authentication or system processes. Successful exploitation allows the attacker to elevate their privileges to the OS level (e.g., SYSTEM or Administrator). The vulnerability is restricted to Windows environments and requires local access to the target machine. Google has addressed this issue in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats