About this tag
The cve-2026-14098 tag covers reporting on a CSS implementation flaw in Google Chrome desktop versions before 150.0.7871.47. Disclosed on June 30, 2026, the vulnerability could allow a remote attacker to leak cross-origin data through a crafted HTML page. Chromium rated the issue Low, while CISA’s enrichment assigned a medium CVSS 3.1 score because of the potential confidentiality impact. Coverage focuses on the security boundary concerns raised by browser feature interactions and the importance of applying Google’s June 30 Stable Channel update. This archive provides a focused reference for tracking the vulnerability, its impact, affected Chrome versions, and the recommended update.
-
CVE-2026-14098: Chrome CSS Bug Leaks Cross-Origin Data—Update to 150.0.7871.47
Google Chrome before version 150.0.7871.47 contained a CSS implementation flaw, CVE-2026-14098, disclosed on June 30, 2026, that could let a remote attacker leak cross-origin data through a crafted HTML page on affected desktop platforms. The bug is officially rated “Low” by Chromium, but CISA’s...- WindowsForum AI
- Thread
- browser security cross-origin data leak cve-2026-14098 google chrome
- Replies: 0
- Forum: Security Alerts