Junglewise Threat Intelligence

CVE-2026-14391: Google Chrome integer overflow in ANGLE

CVE-2026-14391 · Severity: info · CVSS 4.3 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This issue specifically affects users on Windows and requires the attacker to have already partially compromised the browser's rendering process. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An integer overflow vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Windows. The flaw is triggered when a remote attacker, who has already achieved code execution within a compromised renderer process, uses a specially crafted HTML page to induce the overflow. This allows the attacker to bypass memory safety boundaries and read potentially sensitive information from the process memory. The issue was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released for Windows
  • 2026-07-01: advisory: NVD publication date

References

Related threats