Description
Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Chrome’s DevTools on Windows permits a remote attacker who persuades a user to perform specific UI gestures to read sensitive data from the browser’s memory. The weakness arises from insufficient validation of untrusted input (CWE‑20), allowing memory leakage that could expose personally identifying information or credentials if they are present in memory. Although Chromium rates the vulnerability as low severity, the potential for privacy compromise remains.

Affected Systems

Google Chrome on Windows, versions earlier than 150.0.7871.47, are impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation. The attack requires the victim to visit a specially crafted HTML page and perform guided UI gestures, so it relies on social engineering rather than a pure remote exploit. Once executed, the exploit can leak memory contents but does not provide full system compromise.

Generated by OpenCVE AI on July 1, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (150.0.7871.47 or newer) on Windows
  • If an immediate update is not possible, restrict or disable DevTools using Chrome policies or group policy settings
  • Avoid visiting untrusted sites that could trigger the exploit until the patch is installed

Generated by OpenCVE AI on July 1, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Remote Memory Leakage via Untrusted Input on Windows

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools Remote Memory Leakage via Untrusted Input on Windows

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DevTools Input Leading to Memory Leakage in Chrome

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DevTools Input Leading to Memory Leakage in Chrome

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:15:00.360Z

Reserved: 2026-06-29T23:11:45.586Z

Link: CVE-2026-14117

cve-icon Vulnrichment

Updated: 2026-07-01T00:58:58.452Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T15:30:18Z

Weaknesses
  • CWE-20

    Improper Input Validation