CVE-2026-14427Disclosure(google / chrome)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-12: 1Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-12: 107-0307-12
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-07-031
Disclosure1
2026-07-121
Patch1
Full discourse2 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #chrome Chrome 150.0.7871.46/.47 つづき ・CVE-2026-13787 ・CVE-2026-13788 ・CVE-2026-14398 ・CVE-2026-14417 ・CVE-2026-14419 ・CVE-2026-14420 ・CVE-2026-14427

    Post summary

    The tweet simply lists a set of newly disclosed Chrome CVEs without providing further detail, suggesting it is a basic disclosure announcement.

    1000154
    91 followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 Chrome users: update to 150.0.7871.46—CVE-2026-14427 can turn a compromised renderer into a sandbox escape. Defense in depth only works if you patch the first wall. https://windowsforum.com/threads/cve-2026-14427-update-chrome-to-150-0-7871-46-for-skia-sandbox-escape.437191/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SandboxEscape #ChromeSecurity #GoogleChrome #Cve202614427 https://t.co/bBtf0932hd

    Post summary

    The post announces that updating Chrome to version 150.0.7871.46 patches CVE-2026-14427, a sandbox‑escape vulnerability that could let a compromised renderer escape its security boundaries; users are urged to update immediately.

    0000048
    1.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more