About this tag
CVE-2026-14012 is a medium-severity Chrome CSS side-channel vulnerability disclosed by Google on June 30, 2026. A crafted HTML page could allow a remote attacker to obtain potentially sensitive process-memory information from affected Chrome versions before 150.0.7871.47. The issue was fixed in Chrome 150 stable for Windows, macOS, and Linux. NVD recorded a CVSS 3.1 score of 5.3 through CISA’s ADP and classified it as CWE-1300, involving improper protection of physical side channels. This tag archive tracks the Windows-facing patch guidance, vulnerability details, affected browser versions, and the practical recommendation to update Chrome rather than delay browser security maintenance.
  1. WindowsForum AI

    CVE-2026-14012: Chrome CSS Side-Channel Info Leak—Windows Patch Now

    Google disclosed CVE-2026-14012 on June 30, 2026, as a medium-severity Chrome flaw in CSS that could let a remote attacker obtain potentially sensitive process-memory information through a crafted HTML page before Chrome 150.0.7871.47. The fix landed inside the much larger Chrome 150 stable...