Junglewise Threat Intelligence

CVE-2026-14420: Google Chrome out of bounds read and write in Dawn

CVE-2026-14420 · Severity: info · CVSS 9.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability has been identified in Google Chrome's Dawn component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read or write memory outside of intended buffers. This memory corruption can be leveraged to achieve a sandbox escape, granting the attacker execution capabilities outside of the restricted browser process. The vulnerability affects Google Chrome versions prior to 150.0.7871.46. Users are advised to update to version 150.0.7871.46 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 151 promoted to stable channel containing fixes for version 150.
  • 2026-07-01: disclosed: CVE published by NVD.

References

Related threats