Junglewise Threat Intelligence

CVE-2026-14386: Google Chrome out of bounds read in ANGLE

CVE-2026-14386 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A security flaw in its graphics engine could allow a malicious website to read sensitive information from the browser's memory. This could lead to the exposure of private data or help an attacker bypass other security protections.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data outside the intended buffer in the process memory. This can lead to the disclosure of sensitive information from the browser process. The vulnerability was addressed in Google Chrome version 150.0.7871.46 for Windows, Mac, and Linux. Exploitation requires the victim to navigate to a malicious website but does not require prior authentication.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46/.47
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats