Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-14104: Google Chrome: Malicious HTML pages can run unauthorized code
CVE-2026-14104
Summary
A security issue in older versions of Google Chrome allowed a hacker to trick a user into visiting a malicious website. This could potentially allow the hacker to run unauthorized code on the user's device. Users should update to the latest version of Google Chrome to fix this issue.
Original title
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (C...
Original description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd CVSS3.1
8.8
Vulnerability type
CWE-20
Improper Input Validation
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 2 Jul 2026