• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-14382: sandbox escape in Google Chrome

A remote attacker can cause a sandbox escape in Google Chrome by delivering a crafted HTML page that exploits insufficient validation in ANGLE; this is tracked as CVE-2026-14382. The flaw affects Chrome 150.0.7871.46 and earlier builds in the 150.x branch and is fixed in 150.0.7871.46. Exploitation requires that a user load the malicious page (user interaction) and can occur over the network when a victim visits or is directed to the crafted content.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.6CRITICAL
EPSS
0.00345
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — public exploit code exists and the vulnerability allows a browser sandbox escape; update Chrome to 150.0.7871.46 immediately or apply vendor guidance to mitigate exposure.

What is CVE-2026-14382?

A remote attacker can cause a sandbox escape in Google Chrome by delivering a crafted HTML page that exploits insufficient validation in ANGLE; this is tracked as CVE-2026-14382. The flaw affects Chrome 150.0.7871.46 and earlier builds in the 150.x branch and is fixed in 150.0.7871.46. Exploitation requires that a user load the malicious page (user interaction) and can occur over the network when a victim visits or is directed to the crafted content.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
150.x150.0.7871.46 – before 150.0.7871.46150.0.7871.46

Is CVE-2026-14382 being exploited?

Public exploit code is available.

How to fix CVE-2026-14382

  1. Update Google Chrome to version 150.0.7871.46.
  2. Block or restrict access to untrusted web content and disable automatic loading of remote content where feasible.
  3. Monitor endpoint and browser telemetry for suspicious renderer crashes or unexpected child-process activity.
  4. Apply any additional vendor mitigations or enterprise policies recommended by Google.

Frequently asked questions

Is CVE-2026-14382 being actively exploited?

Public exploit code is available for CVE-2026-14382.

Which Chrome versions are affected by CVE-2026-14382?

Chrome builds in the 150.x branch prior to 150.0.7871.46 are affected; the issue is fixed in 150.0.7871.46.

Is there a patch for CVE-2026-14382?

Yes, Google fixed the vulnerability in Chrome version 150.0.7871.46.

Does CVE-2026-14382 require authentication?

No authentication is required; the exploit requires only that a user load a crafted HTML page in Chrome.

References