Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-14037: Google Chrome GPU Policy Bypass via Malicious Page
CVE-2026-14037 · published 1 month ago
Summary
A remote attacker who has already compromised a user's browser can create a malicious webpage that could potentially break out of the browser's security sandbox. This affects users of Google Chrome prior to a specific version. To fix this, update to the latest version of Google Chrome.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chrome |
< 150.0.7871.47 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
Original advisory text
Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft...
Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
References
- https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_... Release Notes
- https://issues.chromium.org/issues/496522611 Permissions Required
Severity
9.6
Critical
CVSS 3.1: 9.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-693Protection Mechanism Failure
Timeline
Published30 Jun 2026
Updated15 Aug 2026
First seen1 Jul 2026
Sources
CVE-2026-14037 · NVD
Monitor software like this
Free during beta