Junglewise Threat Intelligence

CVE-2026-14400: Google Chrome out of bounds write in ANGLE

CVE-2026-14400 · Severity: info · CVSS 8.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's graphics engine could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files, installation of malware, or full control over the user's device.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. By exploiting this memory corruption issue, a remote attacker can potentially achieve a sandbox escape, moving from the restricted renderer process to the more privileged browser process or the host operating system. The vulnerability is fixed in Google Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fixed in Chrome stable channel update 150.0.7871.46
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats