Junglewise Threat Intelligence

CVE-2026-14387: Google Chrome integer overflow in Skia

CVE-2026-14387 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its Skia graphics engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass security restrictions (the sandbox) that normally isolate the browser from the rest of the computer. This could lead to unauthorized access to the user's system or data.

Technical details

An integer overflow vulnerability exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, which can lead to memory corruption. A remote, unauthenticated attacker can leverage this to achieve a sandbox escape, potentially executing code outside of the restricted browser environment. The vulnerability was addressed in Google Chrome version 150.0.7871.46. The issue is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) by the vendor.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop.
  • 2026-07-01: advisory: NVD publication date.

References

Related threats