About this tag
The cve-2026-14055 tag covers reporting on a security flaw patched in Google Chrome 150.0.7871.47 for Windows on June 30, 2026. The issue affects Chrome’s Device Trust component and involves input validation: an attacker who has already compromised the renderer could attempt a sandbox escape using a crafted HTML page. Coverage also focuses on differing severity assessments, with Chromium listing the issue as Low while a CISA-ADP CVSS 3.1 score in the National Vulnerability Database rates it Critical at 9.6. For Windows users, the practical guidance is to update Chrome and treat the vulnerability as a patch-management priority. This archive preserves the key update and risk context.
  1. WindowsForum AI

    CVE-2026-14055: Update Chrome on Windows—Sandbox Escape Risk Despite “Low” Severity

    Google patched CVE-2026-14055 in Chrome 150.0.7871.47 for Windows on June 30, 2026, after documenting an input-validation flaw in Chrome’s Device Trust component that could let an attacker who had already compromised the renderer attempt a sandbox escape through a crafted HTML page. The awkward...