Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-14037: Google Chrome GPU Policy Bypass via Malicious Page

CVE-2026-14037 · published 3 months ago
Summary

A remote attacker who has already compromised a user's browser can create a malicious webpage that could potentially break out of the browser's security sandbox. This affects users of Google Chrome prior to a specific version. To fix this, update to the latest version of Google Chrome.

What to do
  • Update google chrome to version 150.0.7871.47 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian chromium All versions
Debian:12 debian chromium All versions
Debian:13 debian chromium All versions
Debian:14 debian chromium All versions
– google chrome < 150.0.7871.47
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Original advisory text
Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft...
Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Severity
9.6 Critical
CVSS 3.1: 9.6 (NVD)
CVSS 3.1: 9.6 (OSV)
Exploitation
EPSS <1%
Type
CWE-693Protection Mechanism Failure
Timeline
Published30 Jun 2026
Updated27 Sep 2026
First seen1 Jul 2026
Sources
Track software like this
Free during beta