Junglewise Threat Intelligence

CVE-2026-14384: Google Chrome out of bounds read in ANGLE

CVE-2026-14384 · Severity: info · CVSS 4.3 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine (ANGLE) could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of sensitive information across different browser tabs. Google has released an update to address this issue, and users should ensure their browser is updated to the latest version.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Almost Native Graphics Layer Engine (ANGLE) component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin isolation and read data from other origins. This is a client-side attack requiring user interaction (visiting a malicious site). The vulnerability was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released for Windows
  • 2026-07-01: advisory: NVD publication date

References

Related threats