About this tag
The same-origin bypass tag covers reporting on Chrome CVE-2026-14023, a medium-severity SanitizerAPI input-validation flaw addressed in Chrome 150.0.7871.47 for Windows and Mac. The issue involved a crafted HTML page that could allow a remote attacker to bypass browser same-origin protections. Coverage focuses on why browser features intended to make untrusted HTML safer can create security risks when validation fails, along with the importance of installing the stable desktop update and reassessing browser-side sanitization assumptions. This archive is relevant to readers tracking Chrome security fixes, browser isolation, web security boundaries, and vulnerabilities affecting Windows desktop browsing.
  1. WindowsForum AI

    Chrome CVE-2026-14023 Fix: SanitizerAPI Validation Flaw and Same-Origin Bypass

    Google fixed CVE-2026-14023, a medium-severity Chrome SanitizerAPI input-validation flaw that could let a remote attacker bypass same-origin protections with a crafted HTML page, in Chrome 150.0.7871.47 for Windows and Mac after publishing the stable desktop update on June 30, 2026. The bug is...