Junglewise Threat Intelligence

CVE-2026-14389: Google Chrome integer overflow in Skia

CVE-2026-14389 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics engine, Skia. If a user visits a specially crafted website, an attacker who has already gained limited control over the browser's rendering process could bypass security restrictions (the 'sandbox') that normally keep the browser isolated from the rest of the computer. This could potentially allow the attacker to access sensitive files or execute unauthorized commands on the underlying operating system.

Technical details

An integer overflow vulnerability exists in the Skia graphics component of Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within a compromised renderer process can leverage this overflow to perform a sandbox escape, potentially gaining elevated privileges on the host system. The vulnerability is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) by Chromium developers. The issue was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats