Description
Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Chrome’s Device Trust mechanism on Windows fails to validate untrusted input properly, allowing a remote attacker who has already compromised the renderer process to supply a specially crafted HTML page that may cause a browser sandbox escape. The input validation weakness is classified as CWE-20 and is rated as low severity by Chromium, yet it enables execution of code outside the browser sandbox if triggered.

Affected Systems

Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. All stable channel releases prior to that point contain the vulnerability; upgrades to 150.0.7871.47 or later contain the fix.

Risk and Exploitability

The EPSS score remains < 1% and the vulnerability is not listed in KEV, but the CVSS score of 9.6 indicates a critical risk. The likely attack vector is a crafted HTML page served to a user after the attacker has compromised the renderer process. Once the renderer process is compromised, the attacker could then trigger the device trust flaw to escape the sandbox and execute arbitrary code, making the potential impact severe.

Generated by OpenCVE AI on July 17, 2026 at 13:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Chrome update 150.0.7871.47 or later.
  • If an update cannot be applied immediately, disable Device Trust through Chrome flags or command-line switches.
  • Monitor the browser and system logs for unusual renderer activity or sandbox-escape attempts.

Generated by OpenCVE AI on July 17, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Device Trust Validation Flaw Allows Sandbox Escape via Crafted HTML

Wed, 15 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Device Trust Validation Flaw Allows Sandbox Escape via Crafted HTML

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Failure Enabling Sandbox Escape in Chrome

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Failure Enabling Sandbox Escape in Chrome

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Vulnerability in Chrome Allows Sandbox Escape

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Vulnerability in Chrome Allows Sandbox Escape

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Flaw Enabling Sandbox Escape via Crafted HTML

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Flaw Enabling Sandbox Escape via Crafted HTML

Wed, 08 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Validation Flaw Enables Sandbox Escape

Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Validation Flaw Enables Sandbox Escape

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Exploit Enables Sandbox Escape

Sun, 05 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Exploit Enables Sandbox Escape

Sun, 05 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Flaw Enabling Sandbox Escape

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Flaw Enabling Sandbox Escape

Sat, 04 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Flaw Allows Sandbox Escape in Chrome

Sat, 04 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Device Trust Input Validation Flaw Allows Sandbox Escape in Chrome

Fri, 03 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Allows Sandbox Escape via Crafted HTML Page

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Allows Sandbox Escape via Crafted HTML Page

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Vulnerability Enabling Sandbox Escape via Crafted HTML Page

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Vulnerability Enabling Sandbox Escape via Crafted HTML Page

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Glitch Allows Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Input Validation Glitch Allows Sandbox Escape via Crafted HTML

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Sandbox Escape via Crafted HTML Page

Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Chrome Device Trust Sandbox Escape via Crafted HTML Page

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Device Trust Leading to Sandbox Escape via Crafted Page

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Device Trust Leading to Sandbox Escape via Crafted Page

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:53:08.318Z

Reserved: 2026-06-29T23:11:33.108Z

Link: CVE-2026-14055

cve-icon Vulnrichment

Updated: 2026-07-01T13:06:47.920Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation