Junglewise Threat Intelligence

CVE-2026-14412: Google Chrome improper input validation in ANGLE

CVE-2026-14412 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its ANGLE graphics engine. An attacker who has already compromised a browser's rendering process could use this flaw to break out of the security sandbox that normally isolates the browser from the rest of the computer. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

A vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome due to insufficient validation of untrusted input. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and perform a sandbox escape. Exploitation is achieved via a specially crafted HTML page. This issue was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.46 stable channel update.
  • 2026-07-01: advisory: NVD published the CVE record.

References

Related threats