Description
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-01
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the Dawn rendering engine of Google Chrome. When a specially crafted HTML page is parsed, the engine accesses memory beyond the intended buffer, which can leak sensitive data or corrupt execution flow. This bug is classified as CWE‑125 and is capable of allowing a remote attacker to escape the browser’s sandbox and execute code with elevated privileges, potentially compromising the host operating system.

Affected Systems

Google Chrome for desktop is affected. Any Chrome release prior to version 150.0.7871.46 is vulnerable; users running older stable channel builds are at risk.

Risk and Exploitability

The flaw requires an attacker to deliver a crafted HTML page to the vulnerable browser, a plausible scenario for drive‑by attacks or malicious web sites. The CVSS score of 9.6 reflects the high impact and complete remote attack scope. The EPSS score of less than 1 % indicates a low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Although Chromium internally rates the issue as low severity, the potential for sandbox escape means that any successful exploitation would grant the attacker significant control over the host system.

Generated by OpenCVE AI on August 3, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.46 or later, using an enterprise update policy or management tool
  • Ensure that the Chrome sandbox feature remains enabled and that site isolation or sandboxing is not disabled by user or policy settings
  • Enable automatic updates or enforce update compliance through enterprise management, and limit extension permissions to reduce the attack surface

Generated by OpenCVE AI on August 3, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Dawn Rendering Engine Leading to Sandbox Escape

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Dawn Rendering Engine Leading to Sandbox Escape

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome Dawn Rendering Engine Leading to Sandbox Escape

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome Dawn Rendering Engine Leading to Sandbox Escape

Tue, 14 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Dawn Rendering Engine Out‑of‑Bounds Read Leading to Sandbox Escape in Chrome

Sun, 12 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Dawn Rendering Engine Out‑of‑Bounds Read Leading to Sandbox Escape in Chrome

Sat, 11 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Dawn out‑of‑bounds read may allow sandbox escape

Fri, 10 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn out‑of‑bounds read may allow sandbox escape

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read Causing Sandbox Escape in Google Chrome Dawn Engine

Thu, 09 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read Causing Sandbox Escape in Google Chrome Dawn Engine

Wed, 08 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Rendering Engine Allowing Sandbox Escape

Tue, 07 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Rendering Engine Allowing Sandbox Escape

Tue, 07 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome's Dawn Engine Allowing Sandbox Escape

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome's Dawn Engine Allowing Sandbox Escape

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Out-of-Bounds Read Allows Sandbox Escape

Sun, 05 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Out-of-Bounds Read Allows Sandbox Escape

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Engine Allows Potential Sandbox Escape

Sat, 04 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Engine Allows Potential Sandbox Escape

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Rendering Engine Out‑of‑Bounds Read Causing Sandbox Escape

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Rendering Engine Out‑of‑Bounds Read Causing Sandbox Escape

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Engine Allows Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Dawn Engine Allows Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome's Dawn Engine Enables Potential Sandbox Escape

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome's Dawn Engine Enables Potential Sandbox Escape

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:29.159Z

Reserved: 2026-07-01T21:37:32.150Z

Link: CVE-2026-14416

cve-icon Vulnrichment

Updated: 2026-07-02T00:01:27.764Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-01T23:16:50.063

Modified: 2026-07-03T04:17:48.653

Link: CVE-2026-14416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:00:12Z

Weaknesses