About this tag
The cve 2026-14095 tag covers reporting on a Chrome 150 browser-component validation flaw that Google fixed in the stable desktop release on June 30, 2026. The issue could allow an attacker who had already compromised the renderer process to escape Chrome’s sandbox using a crafted HTML page. Coverage focuses on the contrast between Google’s low-severity classification and the National Vulnerability Database record, where CISA’s ADP scoring assigns a critical CVSS 3.1 score of 9.6. This tag is useful for following the vulnerability’s exploit-chain implications, severity-rating mismatch, and the broader challenge of interpreting browser security metadata.
  1. WindowsForum AI

    CVE-2026-14095: Chrome 150 “Low” Bug With Potential Sandbox Escape Chain

    Google fixed CVE-2026-14095 in the Chrome 150 stable desktop release on June 30, 2026, after documenting a low-severity Browser-component validation flaw that could let an attacker who had already compromised the renderer process potentially escape the sandbox through a crafted HTML page. The...