CVE-2026-14387
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-14387 is an integer overflow vulnerability in the Skia graphics rendering engine within Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects all versions of Google Chrome prior to 150.0.7871.46 on Windows, Mac, and Linux. The vulnerability was reported to Google on 2026-04-07 and patched with the Chrome 150 stable channel release on June 30, 2026. It carries a CVSS v3.1 base score of 9.6 (Critical), despite being rated "Medium" severity by Chromium's internal severity scale (Chrome Advisory, GitHub Advisory).

Technical details

The root cause is an integer overflow (CWE-472 — External Control of Assumed-Immutable Web Parameter) in Chrome's Skia graphics library, which handles 2D rendering operations. When processing specially crafted graphical content within a malicious HTML page, an arithmetic overflow condition can be triggered in Skia, potentially corrupting memory in a way that allows an attacker to escape Chrome's sandbox. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page. The Chromium issue tracker entry for this bug is tracked under issue ID 500305404 (Chrome Advisory, GitHub Advisory).

Impact

Successful exploitation could allow a remote attacker to escape Chrome's sandbox and execute arbitrary code outside the restricted browser process environment, resulting in high impact to confidentiality, integrity, and availability of the affected system. Because the scope is marked as "Changed," a successful exploit can affect resources beyond the Chrome renderer process itself, potentially enabling full system compromise. The attack requires no privileges and only minimal user interaction (visiting a malicious page), making it accessible to a broad range of threat actors (GitHub Advisory, Chrome Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 150.0.7871.46 on Windows, Mac, or Linux using browser fingerprinting or social engineering.
  2. Craft malicious HTML page: Develop a web page containing specially crafted graphical content (e.g., canvas operations, SVG, or CSS rendering triggers) designed to induce an integer overflow in Chrome's Skia rendering engine.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website — user interaction (page visit) is required.
  4. Trigger the integer overflow: When Chrome renders the malicious content, the Skia library processes the crafted input, causing an arithmetic overflow that corrupts memory within the renderer process.
  5. Achieve sandbox escape: Leverage the memory corruption condition to break out of Chrome's sandbox, potentially enabling arbitrary code execution on the host system with the privileges of the Chrome process (Chrome Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome process to unknown external IP addresses or domains following a web page visit; unusual DNS lookups initiated by the browser process.
  • Process: Unusual child processes spawned by the Chrome renderer process (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) that are not typical browser subprocesses.
  • Logs: Browser crash reports or renderer process termination events coinciding with visits to unfamiliar or suspicious URLs; Windows Event Log entries showing new process creation by Chrome child processes.
  • File System: Unexpected files written to disk by the Chrome process or its children, particularly in temp directories or user profile folders; new scheduled tasks or persistence mechanisms created shortly after a browser session.

Mitigation and workarounds

Google has released a patch in Chrome 150.0.7871.46 (Linux) and 150.0.7871.46/.47 (Windows/Mac), which addresses this vulnerability along with 432 other security fixes. Users should update Google Chrome to version 150.0.7871.46 or later immediately by navigating to chrome://settings/help or enabling automatic updates. As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites and consider using browser isolation technologies where available (Chrome Advisory).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15767HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium-headless-debuginfo
NoYesJul 14, 2026
CVE-2026-15769HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui
NoYesJul 14, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-common
NoYesJul 14, 2026
CVE-2026-15768MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesJul 14, 2026
CVE-2026-15766MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-qt6-ui-debuginfo
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management