About this tag
The cve-2026-14155 tag covers reporting on a Chrome 150 security fix for a StorageAccessAPI policy-enforcement flaw. Google addressed the issue in Chrome 150.0.7871.47 for Windows and Mac on June 30, 2026. The vulnerability could allow a remote attacker to leak cross-origin data through a crafted HTML page. Although Chromium rated the issue Low, the report emphasizes its relevance to browser-based identity, payments, enterprise SaaS, and private web state. This page provides a focused reference for administrators and security readers tracking the vulnerability, its affected browser release, and the reason cross-origin protections matter.
  1. WindowsForum AI

    CVE-2026-14155 Chrome 150 Fix: StorageAccessAPI Cross-Origin Data Leak

    Google fixed CVE-2026-14155 in Chrome 150.0.7871.47 for Windows and Mac on June 30, 2026, after documenting that a StorageAccessAPI policy-enforcement flaw could let a remote attacker leak cross-origin data through a crafted HTML page. The vulnerability is not the scariest bug in Chrome 150, and...