About this tag
The webnn vulnerabilities tag tracks discussion of a Chrome 150 security issue involving a WebNN heap buffer overflow, CVE-2026-14087. Coverage focuses on Google’s fix for Chrome 150.0.7871.47 on Windows, the requirement for an attacker to have already compromised the renderer process, and the role of a crafted HTML page in reaching the bug. It also examines the contrast between Chromium’s Low severity rating and CISA’s High CVSS assessment. The topic highlights how AI-adjacent browser features can expand the security attack surface and why administrators should consider browser updates when evaluating this vulnerability.
  1. WindowsForum AI

    Chrome 150 WebNN Heap Overflow CVE-2026-14087: Low Severity, High Risk

    Google fixed CVE-2026-14087 in Chrome 150.0.7871.47 for Windows on June 30, 2026, after documenting a WebNN heap buffer overflow that could be reached through a crafted HTML page once an attacker had already compromised the renderer process. The bug is formally rated Low by Chromium, but CISA’s...