Junglewise Threat Intelligence

CVE-2026-14156: Google Chrome same origin policy bypass in StorageAccessAPI

CVE-2026-14156 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security flaw in the way the browser manages website storage permissions could allow a malicious website to access data belonging to other websites. This bypasses a fundamental security boundary known as the Same-Origin Policy, potentially leading to the unauthorized access of sensitive user information or session data.

Technical details

A vulnerability exists in the StorageAccessAPI component of Google Chrome due to insufficient policy enforcement. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw using a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP), granting unauthorized access to storage data across different origins. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats