Junglewise Threat Intelligence

CVE-2026-14392: Google Chrome out of bounds write in Tint

CVE-2026-14392 · Severity: info · CVSS 8.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Tint component, which is responsible for handling graphics shaders. By tricking a user into visiting a specially crafted website, an attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Tint, the compiler for the WebGPU Shading Language (WGSL) in Google Chrome. The flaw is present in versions prior to 150.0.7871.46. A remote attacker can exploit this by enticing a user to visit a malicious website containing a specially crafted HTML page and shader code. Successful exploitation could lead to memory corruption, allowing the attacker to escape the Chrome renderer sandbox and execute arbitrary code on the host system. Google has addressed this vulnerability in the stable channel update 150.0.7871.46 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.46/.47
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats