Description
Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw in Chrome’s Tint component, present in all builds prior to 150.0.7871.46, can be triggered by a specially crafted HTML page. Owing to the vulnerability (CWE‑787), a remote attacker could potentially escape the browser sandbox and execute code with the privileges of the browser process. The CVE description notes that the escape is "potentially" achievable, meaning the exploitation outcome depends on successfully triggering the out‑of‑bounds write.

Affected Systems

All desktop instances of Google Chrome older than 150.0.7871.46, across Windows, macOS, and Linux, are susceptible to the flaw and must install the patched revision before processing untrusted HTML content.

Risk and Exploitability

Chromium rates the issue with a CVSS score of 9.6, indicating very high severity. The EPSS score of <1% suggests that real‑world exploitation is unlikely but not impossible. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote: an attacker must persuade the victim’s browser to parse a malicious HTML document, typically via a link or embedded content. Successful exploitation would yield sandbox escape and the ability to run code at the browser process level.

Generated by OpenCVE AI on July 21, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.46 or later.
  • Ensure the browser sandbox remains enabled, either via default settings or by verifying relevant Chrome flags or system policies.
  • Enforce strict content‑security policies to restrict processing of malicious HTML content.

Generated by OpenCVE AI on July 21, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome’s Tint Allows Sandbox Escape

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome’s Tint Allows Sandbox Escape

Wed, 15 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Chrome Tint Component Out‑of‑Bounds Write Causing Potential Sandbox Escape

Mon, 13 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome Tint Component Out‑of‑Bounds Write Causing Potential Sandbox Escape

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chromium Tint Out-of-Bounds Write Enables Potential Sandbox Escape

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chromium Tint Out-of-Bounds Write Enables Potential Sandbox Escape

Sat, 11 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome Tint Leading to Sandbox Escape

Fri, 10 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome Tint Leading to Sandbox Escape

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Tint component out-of-bounds write potentially enables sandbox escape in Chrome

Thu, 09 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Tint component out-of-bounds write potentially enables sandbox escape in Chrome

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome's Tint Component Enabling Sandbox Escape

Wed, 08 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome's Tint Component Enabling Sandbox Escape

Mon, 06 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome Tint Enabling Potential Sandbox Escape

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome Tint Enabling Potential Sandbox Escape

Sun, 05 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Tint Out‑of‑Bounds Write Enabling Browser Sandbox Escape

Sat, 04 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Tint Out‑of‑Bounds Write Enabling Browser Sandbox Escape

Sat, 04 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome’s Tint Rendering Allows Remote Sandbox Escape

Sat, 04 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Chrome’s Tint Rendering Allows Remote Sandbox Escape

Fri, 03 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome Tint Allows Sandbox Escape

Fri, 03 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Chrome Tint Allows Sandbox Escape

Fri, 03 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome out‑of‑bounds write in Tint enabling sandbox escape via crafted HTML

Thu, 02 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome out‑of‑bounds write in Tint enabling sandbox escape via crafted HTML

Thu, 02 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:26.980Z

Reserved: 2026-07-01T21:37:26.470Z

Link: CVE-2026-14392

cve-icon Vulnrichment

Updated: 2026-07-02T00:01:18.644Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:00:04Z

Weaknesses