Junglewise Threat Intelligence

CVE-2026-14145: Google Chrome UXSS in CSS implementation

CVE-2026-14145 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles CSS (Cascading Style Sheets) could allow a malicious website to inject unauthorized scripts or HTML into other websites you are visiting. This could lead to the theft of sensitive information or unauthorized actions being taken in your name on other sites.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS implementation. The flaw stems from an inappropriate implementation that fails to properly isolate or validate CSS-related operations, allowing a remote attacker to bypass the Same-Origin Policy (SOP). By convincing a user to visit a specially crafted HTML page, an attacker can execute arbitrary JavaScript or inject HTML into the context of any website currently open in the browser. This vulnerability was addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats