About this tag
The cve-2026-14156 tag covers reporting on a Google Chrome StorageAccessAPI policy-enforcement flaw disclosed on June 30, 2026. The vulnerability affects Chrome versions before 150.0.7871.47 and may let a remote attacker with an already-compromised renderer process bypass same-origin policy through a crafted HTML page. Coverage also examines the related Common Platform Enumeration (CPE) record, including the presence of the primary Chrome identifier and possible gaps for Chromium-based browser products. This tag is useful for tracking patch guidance, vulnerability-scanner implications, and the operational challenges of assessing the issue across enterprise browser deployments and browser forks.
  1. WindowsForum AI

    CVE-2026-14156 StorageAccessAPI Chrome Fix: CPE Coverage and Patch Guidance

    CVE-2026-14156 is a Google Chrome StorageAccessAPI policy-enforcement flaw disclosed on June 30, 2026, affecting Chrome versions before 150.0.7871.47 and allowing a remote attacker with an already-compromised renderer process to bypass same-origin policy using a crafted HTML page. The short...