Junglewise Threat Intelligence

CVE-2026-14427: Google Chrome heap buffer overflow in Skia

CVE-2026-14427 · Severity: info · CVSS 9.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's Skia graphics engine. This flaw could allow a malicious website to bypass the browser's security sandbox, which is the primary layer of defense that prevents websites from accessing your computer's files or private data. If exploited, an attacker who has already compromised a browser tab could gain full control over the underlying system.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in the Skia graphics library within Google Chrome. The vulnerability is reachable via a crafted HTML page. An attacker who has already achieved code execution within a compromised renderer process can leverage this overflow to escape the Chrome sandbox and execute arbitrary code on the host operating system. This issue was addressed in Google Chrome version 150.0.7871.46 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop.
  • 2026-07-01: disclosed: CVE published to NVD.

References

Related threats