Description
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient validation of untrusted input in Chrome DevTools. A crafted page can induce a user to perform specific UI gestures within DevTools, causing the browser to expose cross‑origin data. This flaw, classified as CWE‑20, results in information disclosure but does not grant arbitrary code execution.

Affected Systems

All Google Chrome installations older than version 150.0.7871.47 on any platform are vulnerable. Users who view malicious pages that prompt them to interact with DevTools can experience the data leak.

Risk and Exploitability

The CVSS score of 4.3 categorizes the issue as Low severity, and the EPSS score of less than 1% coupled with its absence from the CISA KEV catalog suggests a low likelihood of widespread exploitation. The requirement for deliberate user interaction with the page’s UI gestures further mitigates immediate risk, although the potential for sensitive data exfiltration remains if users comply.

Generated by OpenCVE AI on July 17, 2026 at 13:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or newer
  • Implement an enterprise policy that disables DevTools for untrusted web content
  • Educate users to avoid opening DevTools on unfamiliar or unexpected pages that request UI gestures

Generated by OpenCVE AI on July 17, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Insufficient DevTools Input Validation Allows Cross‑Origin Data Leakage

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Input Validation Flaw Enables Cross‑Origin Data Leakage

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Input Validation Flaw Enables Cross‑Origin Data Leakage

Sun, 12 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome DevTools Allows Cross‑Origin Data Leakage

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome DevTools Allows Cross‑Origin Data Leakage

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leakage Vulnerability

Wed, 08 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leakage Vulnerability

Tue, 07 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leak due to Insufficient Input Validation

Tue, 07 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leak due to Insufficient Input Validation

Mon, 06 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leak via Insufficient Input Validation

Mon, 06 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross‑Origin Data Leak via Insufficient Input Validation

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross-Origin Data Leak via Untrusted Input

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Cross-Origin Data Leak via Untrusted Input

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Input Validation Failure Allows Cross‑Origin Data Leakage

Sat, 04 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Input Validation Failure Allows Cross‑Origin Data Leakage

Fri, 03 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Chrome DevTools Through Improper Input Validation

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Chrome DevTools Through Improper Input Validation

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome DevTools Leading to Cross‑Origin Data Leakage

Thu, 02 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome DevTools Leading to Cross‑Origin Data Leakage

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Chrome DevTools Input Validation Flaw

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Chrome DevTools Input Validation Flaw

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome DevTools leads to cross‑origin data leakage via crafted page

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome DevTools leads to cross‑origin data leakage via crafted page

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:34:58.097Z

Reserved: 2026-06-29T23:11:45.398Z

Link: CVE-2026-14116

cve-icon Vulnrichment

Updated: 2026-07-01T15:06:03.688Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:45:05Z

Weaknesses
  • CWE-20

    Improper Input Validation