About this tag
The nvd cpe discrepancy tag covers a Chrome vulnerability record where NVD metadata and affected-version details do not align cleanly. The discussion focuses on CVE-2026-14061, a Chromium Dawn information-disclosure flaw fixed in Chrome 150.0.7871.47. NVD’s change log appears to describe versions up to but excluding an earlier build, while the CVE description and Chrome-origin affected record identify 150.0.7871.47 as the fixed boundary. The tag is useful for following how CPE version discrepancies, differing severity enrichment from CISA, and inconsistent vulnerability metadata can affect automated patch-compliance checks and create operational noise for defenders.
-
Chrome CVE-2026-14061 Metadata Mismatch: Patch to 150.0.7871.47
Google Chrome CVE-2026-14061 is a low-severity Chromium Dawn information-disclosure flaw fixed in Chrome 150.0.7871.47, published by NVD on June 30, 2026, and later enriched by CISA with a medium CVSS 3.1 score tied to crafted HTML and user interaction. The oddity is not the bug itself; it is...- WindowsForum AI
- Security
- chrome security cve patching nvd cpe discrepancy webgpu dawn flaw
- Replies: 0
- Forum: Security Alerts