
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14387 is an integer overflow vulnerability in the Skia graphics rendering engine within Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects all versions of Google Chrome prior to 150.0.7871.46 on Windows, Mac, and Linux. The vulnerability was reported to Google on 2026-04-07 and patched with the Chrome 150 stable channel release on June 30, 2026. It carries a CVSS v3.1 base score of 9.6 (Critical), despite being rated "Medium" severity by Chromium's internal severity scale (Chrome Advisory, GitHub Advisory).
The root cause is an integer overflow (CWE-472 — External Control of Assumed-Immutable Web Parameter) in Chrome's Skia graphics library, which handles 2D rendering operations. When processing specially crafted graphical content within a malicious HTML page, an arithmetic overflow condition can be triggered in Skia, potentially corrupting memory in a way that allows an attacker to escape Chrome's sandbox. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page. The Chromium issue tracker entry for this bug is tracked under issue ID 500305404 (Chrome Advisory, GitHub Advisory).
Successful exploitation could allow a remote attacker to escape Chrome's sandbox and execute arbitrary code outside the restricted browser process environment, resulting in high impact to confidentiality, integrity, and availability of the affected system. Because the scope is marked as "Changed," a successful exploit can affect resources beyond the Chrome renderer process itself, potentially enabling full system compromise. The attack requires no privileges and only minimal user interaction (visiting a malicious page), making it accessible to a broad range of threat actors (GitHub Advisory, Chrome Advisory).
cmd.exe, powershell.exe, /bin/bash, curl, wget) that are not typical browser subprocesses.Google has released a patch in Chrome 150.0.7871.46 (Linux) and 150.0.7871.46/.47 (Windows/Mac), which addresses this vulnerability along with 432 other security fixes. Users should update Google Chrome to version 150.0.7871.46 or later immediately by navigating to chrome://settings/help or enabling automatic updates. As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites and consider using browser isolation technologies where available (Chrome Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."