Junglewise Threat Intelligence

CVE-2026-14416: Google Chrome out of bounds read in Dawn

CVE-2026-14416 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a remote attacker to bypass security protections. By tricking a user into visiting a specially crafted website, an attacker could potentially escape the browser's 'sandbox,' which is designed to keep malicious code from affecting the rest of the computer. This could lead to unauthorized access to the user's system or data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of intended buffers. This memory corruption can be leveraged to achieve a sandbox escape, potentially allowing code execution outside of the restricted browser environment. The vulnerability is addressed in Chrome version 150.0.7871.46 for Linux and 150.0.7871.46/.47 for Windows and Mac. Google classified this issue with a 'Low' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel.
  • 2026-07-01: advisory: NVD publication date.

References

Related threats