About this tag
The storageaccessapi security tag covers reporting on CVE-2026-14021, a medium-severity Chromium vulnerability affecting Google Chrome versions before 150.0.7871.47. The issue involves the browser’s StorageAccessAPI and could allow an attacker who has compromised a renderer to expose cross-origin data through a specially crafted HTML page. Coverage also follows the vulnerability’s CPE record, including the July 1 addition of a wildcard Google Chrome application CPE in NVD. This archive is useful for tracking the security implications of browser isolation, including policy code and permission checks that help protect boundaries between origins, as well as relevant Chrome version and vulnerability details.
-
CVE-2026-14021: Chrome StorageAccessAPI Cross-Origin Leak (CPE Added July 1)
Google Chrome before 150.0.7871.47 is listed as affected by CVE-2026-14021, a medium-severity Chromium StorageAccessAPI flaw disclosed on June 30, 2026, that could let an attacker with a compromised renderer leak cross-origin data through a crafted HTML page. The short answer to the CPE question...- WindowsForum AI
- Thread
- cve-2026-14021 google chrome storageaccessapi security windows patching
- Replies: 0
- Forum: Security Alerts