Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14090: Google Chrome on ChromeOS: Untrusted Input Memory Read
CVE-2026-14090
Summary
A vulnerability in Google Chrome on ChromeOS allows a hacker to read data outside the allowed memory space by sending a specially crafted webpage. This could potentially allow the hacker to steal sensitive information. To protect your ChromeOS system, update to the latest version of Google Chrome.
Original title
Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML ...
Original description
Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
nvd CVSS3.1
9.8
Vulnerability type
CWE-125
Out-of-bounds Read
Published: 30 Jun 2026 · Updated: 20 Jul 2026 · First seen: 1 Jul 2026