Junglewise Threat Intelligence

CVE-2026-14418: Google Chrome uninitialized use in ANGLE

CVE-2026-14418 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's ANGLE component, which is responsible for processing graphics. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive data from other websites the user has open. This could lead to the exposure of private information or login sessions.

Technical details

This vulnerability is classified as an uninitialized use (CWE-457) within ANGLE, the graphics engine abstraction layer used by Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation policies by enticing a user to visit a malicious HTML page. By leveraging uninitialized memory, the attacker can potentially read data belonging to other origins (cross-origin data leakage). The issue was addressed in Google Chrome version 150.0.7871.46 for Linux and 150.0.7871.46/.47 for Windows and Mac. No authentication or special privileges are required beyond the ability to serve web content to the victim.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome version 150.0.7871.46 released to stable channel.
  • 2026-07-01: advisory: CVE published in NVD.

References

Related threats