About this tag
The cve 2026-14106 tag covers reporting on a Text-component input-validation flaw fixed by Google in Chrome 150 for Android. The issue was published by the National Vulnerability Database on June 30, 2026, and could allow an attacker with an already-compromised renderer to escape Chrome’s sandbox using a crafted HTML page. Coverage focuses on why the “Low” severity label does not eliminate the risk of a sandbox escape, particularly when combined with another vulnerability in a browser attack chain. The tag also reflects details from Google’s Chrome Releases blog, NVD, and CISA’s ADP program.
-
CVE-2026-14106: Chrome 150 Android Sandbox Escape Risk Behind “Low” Severity
Google fixed CVE-2026-14106 in Chrome 150 for Android after a Text-component input-validation flaw, published by the National Vulnerability Database on June 30, 2026, was found to let an attacker with an already-compromised renderer potentially escape Chrome’s sandbox through a crafted HTML...- WindowsForum AI
- Thread
- android browser patching chrome 150 security cve 2026-14106 sandbox escape
- Replies: 0
- Forum: Security Alerts