CVE-2026-14382PoC(google / chrome)

HIGHCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (5 mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked at 5 mentions on most recent observed day (2026-08-19)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-07-02: 1Mentions · 2026-07-08: 2Mentions · 2026-08-19: 5PoC Mentioned / Linked · 2026-07-08: 2PoC Mentioned / Linked · 2026-08-19: 5Exploit Tool / Code · 2026-07-08: 2Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-08: 207-0207-0808-19
Signal classification3 categories
PoC
675.0%
Patch
112.5%
Active Exploitation
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-021
Patch1
2026-07-082
PoC2
2026-08-195
Active Exploitation1PoC4
Full discourse8 posts
  • xvonfers@xvonfers
    Patch

    woah (CVE-2026-14382)[250k$][492218546][ANGLE] https://chromium-review.googlesource.com/c/angle/angle/+/7864196

    Post summary

    The post references CVE‑2026‑14382 and links to a Chromium review that likely contains the patch, but provides no other technical or exploitation details.

    252915117.3K
    5.0K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-14382 PT ID: PT-2026-54649 Vendor: Google Product: Chrome Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-54649 • https://github.com/jaf0rk/CVE-2026-14382 #dbugs_vuln

    Post summary

    A PoC and exploit code for CVE‑2026‑14382 have been published; the vulnerability allows a sandbox escape in Chrome via a crafted HTML page, but no active exploitation has been reported.

    05031173.9K
    3.4K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:54 UTC: Thread live on @lyrie_ai. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-14382

    Post summary

    A Proof of Concept/exploit for CVE-2026-14382 has been announced, but no details on exploitation methods, active attacks, patches, or technical specifics are provided.

    1000044
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    10:40 UTC: First exploit attempt in the wild. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-14382

    Post summary

    The text reports an initial in-the-wild exploitation attempt for CVE-2026-14382, with a PoC/exploit discovered.

    1000049
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:51 UTC: GPT-5 enrichment complete. 69 words. 1 citations. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-14382

    Post summary

    The tweet announces that a proof‑of‑concept exploit has been discovered for CVE‑2026‑14382, but offers no further technical or patch details.

    1000036
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:40 UTC: CVE-2026-14382 disclosed. A PoC/exploit has been discovered for vulnerability CVE-2026-14382 PT ID: PT-2026-54649 Vendor: Google Product: Chrome

    Post summary

    A PoC/exploit for CVE-2026-14382 was disclosed, confirming proof of concept development but lacking detailed code, patch, or active exploitation information.

    1000074
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    07:43 UTC: Lyrie Sentinel flagged it. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-14382

    Post summary

    0day Intel reports a PoC/exploit discovery for CVE-2026-14382, but provides no additional context on exploitation, patching, or technical specifics.

    1000039
    324 followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-14382: A PoC has been released for a Google Chrome vulnerability that could allow a sandbox escape via a crafted HTML page. The issue affects versions prior to 150.0.7871.46. 🔗 https://github.com/jaf0rk/CVE-2026-14382 #CyberSecurity #CVE #Chrome #ThreatWire

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑14382 has been published, detailing a sandbox escape via a crafted HTML page, but no evidence of in‑the‑wild exploitation or patches is mentioned.

    0001090
    65 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more