DIRAS TAKE
Urgent — public exploit code exists and the vulnerability allows a browser sandbox escape; update Chrome to 150.0.7871.46 immediately or apply vendor guidance to mitigate exposure.
What is CVE-2026-14382?
A remote attacker can cause a sandbox escape in Google Chrome by delivering a crafted HTML page that exploits insufficient validation in ANGLE; this is tracked as CVE-2026-14382. The flaw affects Chrome 150.0.7871.46 and earlier builds in the 150.x branch and is fixed in 150.0.7871.46. Exploitation requires that a user load the malicious page (user interaction) and can occur over the network when a victim visits or is directed to the crafted content.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 150.x | 150.0.7871.46 – before 150.0.7871.46 | 150.0.7871.46 |
Is CVE-2026-14382 being exploited?
Public exploit code is available.
How to fix CVE-2026-14382
- Update Google Chrome to version 150.0.7871.46.
- Block or restrict access to untrusted web content and disable automatic loading of remote content where feasible.
- Monitor endpoint and browser telemetry for suspicious renderer crashes or unexpected child-process activity.
- Apply any additional vendor mitigations or enterprise policies recommended by Google.
Frequently asked questions
Is CVE-2026-14382 being actively exploited?
Public exploit code is available for CVE-2026-14382.
Which Chrome versions are affected by CVE-2026-14382?
Chrome builds in the 150.x branch prior to 150.0.7871.46 are affected; the issue is fixed in 150.0.7871.46.
Is there a patch for CVE-2026-14382?
Yes, Google fixed the vulnerability in Chrome version 150.0.7871.46.
Does CVE-2026-14382 require authentication?
No authentication is required; the exploit requires only that a user load a crafted HTML page in Chrome.
References
- nvd.nist.gov/vuln/detail/CVE-2026-14382
- cve.org/CVERecord?id=CVE-2026-14382
- chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
- issues.chromium.org/issues/492218546
- All Google CVEs on CVE Radar
- CVEs published in September 2026