Junglewise Threat Intelligence

CVE-2026-14429: Google Chrome input validation vulnerability in Skia

CVE-2026-14429 · Severity: info · CVSS 8.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its Skia graphics engine could allow a remote attacker to bypass the browser's security sandbox. If exploited, this could allow an attacker who has already gained a foothold in the browser to gain broader access to the underlying operating system and user data.

Technical details

An insufficient validation of untrusted input vulnerability exists in the Skia graphics library within Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This bypasses the security boundaries intended to isolate the browser process from the host operating system. The vulnerability is addressed in Google Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46/.47
  • 2026-07-01: disclosed: CVE published

References

Related threats