Description
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate handling of security-sensitive information in the Enterprise component of Google Chrome before version 150.0.7871.47 allows a remote attacker to read data from process memory. By luring a user to perform specific UI gestures on a crafted HTML page, the attacker can extract potentially private or confidential material. The weakness is identified as CWE‑203, which represents improper protection of information that may lead to disclosure.

Affected Systems

The vulnerability affects all Google Chrome browsers that use the Enterprise implementation and run any version earlier than 150.0.7871.47. Versions released after this patch are not impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The attack requires user interaction with a malicious web page and specific UI gestures, which means it depends on social engineering or user cooperation. Once the user engages the required gestures, information can leak from memory, but remote code execution is not possible.

Generated by OpenCVE AI on July 1, 2026 at 13:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later.
  • Configure enterprise policy to block or restrict access to the Enterprise features that are affected, limiting exposure to untrusted web content.
  • Educate users about the risks of clicking on suspicious links or performing unexpected UI gestures and promote safe browsing practices.

Generated by OpenCVE AI on July 1, 2026 at 13:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Memory Dump via Crafted HTML in Chrome Enterprise

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Memory Disclosure in Chrome via Crafted HTML

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Memory Disclosure in Chrome via Crafted HTML

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T00:59:53.181Z

Reserved: 2026-06-29T23:11:44.618Z

Link: CVE-2026-14112

cve-icon Vulnrichment

Updated: 2026-07-01T00:59:49.333Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T13:45:02Z

Weaknesses