Junglewise Threat Intelligence

CVE-2026-14401: Google Chrome ANGLE insufficient input validation sandbox escape

CVE-2026-14401 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android within the ANGLE graphics component. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering process could bypass security boundaries (the sandbox) that normally keep web content isolated from the rest of the device. This could lead to further unauthorized access to the user's device or data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Android. The flaw allows a remote attacker to achieve a sandbox escape if they have already achieved code execution within the renderer process. The attack is delivered via a crafted HTML page. By providing malicious input that the ANGLE component fails to properly validate, the attacker can break out of the process isolation layer. This vulnerability is addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop/Android versions.
  • 2026-07-01: advisory: NVD published the CVE record.

References

Related threats