Junglewise Threat Intelligence

CVE-2026-14397: Google Chrome out of bounds write in ANGLE on Mac

CVE-2026-14397 · Severity: info · CVSS 6.5 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Mac could allow a malicious website to bypass security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially escape the browser's 'sandbox,' which is designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the user's system or data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics engine abstraction layer used by Google Chrome, specifically affecting the Mac platform. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to write data outside of intended memory buffers. This memory corruption can be leveraged to achieve a sandbox escape, potentially allowing code execution outside of the restricted browser process. The vulnerability was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released for Mac and Windows.
  • 2026-07-01: disclosed: CVE-2026-14397 published.

References

Related threats