Description
Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome before version 150.0.7871.47 contains an insufficient data validation flaw in NetworkCache, classified as CWE‑20. A maliciously crafted HTML page can cause the browser to read cached responses from other origins, allowing a remote attacker to leak confidential data stored in the cache. The vulnerability does not enable code execution or privilege escalation; it merely exposes sensitive information that a user has already requested from another site.

Affected Systems

All installations of Google Chrome running a version older than 150.0.7871.47 on any platform are susceptible. The advisory for the stable channel and the absence of platform restrictions imply that every operating system that ships the affected Chrome version may be in scope.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity. The EPSS score of < 1 %, or approximately 0.24 %, shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a malicious or compromised web page that delivers the crafted payload to a victim’s browser while the browser caches cross‑origin responses.

Generated by OpenCVE AI on August 3, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Chrome update to 150.0.7871.47 or newer through the standard update channel.
  • Enable automatic browser updates to receive future security patches promptly.
  • After upgrading, clear the browser cache to remove any cached data that could have been exploited.

Generated by OpenCVE AI on August 3, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Insufficient NetworkCache Validation Leads to Cross‑Origin Data Leakage in Chrome

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Chrome

Wed, 22 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Chrome

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Chrome

Mon, 13 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Chrome

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Chrome Browser Cross‑Origin Data Leakage via Insufficient Data Validation in NetworkCache

Fri, 10 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Browser Cross‑Origin Data Leakage via Insufficient Data Validation in NetworkCache

Thu, 09 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome NetworkCache Allows Cross-Origin Data Leakage

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome NetworkCache Allows Cross-Origin Data Leakage

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in NetworkCache Causes Cross‑Origin Data Leakage in Google Chrome

Tue, 07 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in NetworkCache Causes Cross‑Origin Data Leakage in Google Chrome

Mon, 06 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Data Validation Flaw in Chrome NetworkCache Enables Cross‑Origin Data Leakage

Sun, 05 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Data Validation Flaw in Chrome NetworkCache Enables Cross‑Origin Data Leakage

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient data validation in NetworkCache leads to cross‑origin data leakage via crafted HTML page

Sat, 04 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Insufficient data validation in NetworkCache leads to cross‑origin data leakage via crafted HTML page

Sat, 04 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Inadequate NetworkCache Validation in Google Chrome

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Inadequate NetworkCache Validation in Google Chrome

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Google Chrome

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via NetworkCache in Google Chrome

Thu, 02 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage in Chrome NetworkCache via Insufficient Data Validation
Weaknesses CWE-200

Wed, 01 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage in Chrome NetworkCache via Insufficient Data Validation
Weaknesses CWE-200

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Insufficient NetworkCache Validation in Chrome
Weaknesses CWE-200
CWE-79

Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Insufficient NetworkCache Validation in Chrome
Weaknesses CWE-200
CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:51:18.923Z

Reserved: 2026-06-29T23:11:42.158Z

Link: CVE-2026-14100

cve-icon Vulnrichment

Updated: 2026-07-01T15:49:08.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation