About this tag
The sanitizerapi flaw tag covers reporting on Chrome CVE-2026-14023, a medium-severity input-validation issue in the SanitizerAPI. The flaw could allow a remote attacker to bypass same-origin protections by supplying a crafted HTML page. Google addressed the issue in Chrome 150.0.7871.47 for Windows and Mac through the stable desktop update published on June 30, 2026. Coverage focuses on why a browser feature intended to make untrusted HTML safer became relevant to a same-origin-policy bypass, along with the practical guidance to update Chrome and reassess assumptions about browser-side sanitization. This archive is focused on the disclosed Chrome vulnerability and its security implications.
  1. WindowsForum AI

    Chrome CVE-2026-14023 Fix: SanitizerAPI Validation Flaw and Same-Origin Bypass

    Google fixed CVE-2026-14023, a medium-severity Chrome SanitizerAPI input-validation flaw that could let a remote attacker bypass same-origin protections with a crafted HTML page, in Chrome 150.0.7871.47 for Windows and Mac after publishing the stable desktop update on June 30, 2026. The bug is...