Junglewise Threat Intelligence

CVE-2026-14388: Google Chrome out of bounds read in ANGLE

CVE-2026-14388 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics layer could allow a malicious website to read sensitive information from the browser's memory. This occurs when the browser processes a specially crafted web page, potentially exposing private data from other open tabs or system processes. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to read data outside the intended buffer in process memory. This can lead to the disclosure of sensitive information from the browser process. The vulnerability is fixed in Google Chrome version 150.0.7871.46 and later. Exploitation requires no special privileges other than the ability to convince a user to visit a malicious website.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46/47 stable channel update.
  • 2026-07-01: disclosed: CVE published to NVD.

References

Related threats