CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-14387

CVSS 9.6v3.1pub. 2026-07-01upd. 2026-07-03

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

🤖 AI Analysis
How it works

The vulnerability consists of an integer overflow error in the Skia component — a 2D graphics engine used by Chrome to render content. An attacker can provide a specially crafted HTML page whose processing triggers incorrect arithmetic calculations leading to overflow. This results in unpredictable memory behavior that can be exploited to break out of the browser's isolated execution environment (sandbox). CWE-472 indicates improper handling of externally controlled numerical values.

Impact

An attacker may potentially execute a Chrome sandbox escape, which can lead to execution of malicious code outside the browser environment, and consequently to taking control over the victim's system.

Mitigation & patch

Google Chrome should be updated to version 150.0.7871.46 or newer. The update is available through Chrome's built-in update mechanism or on the manufacturer's website according to the references.

Who is affected

Google Chrome versions earlier than 150.0.7871.46

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Google Chrome

    APP
    Google
    < 150.0.7871.46
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox