Description
Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome’s Tint rendering component contains a bug that allows an attacker to read from and write to memory locations outside the bounds of the intended buffer. The flaw is triggered by a specially crafted HTML page and is classified under CWE-125 and CWE-787. While the immediate effect is memory corruption and potential application instability, the primary risk is that a successful exploit could compromise the confidentiality or integrity of data handled by the browser and could lead to a browser crash.

Affected Systems

All users running Google Chrome versions earlier than 150.0.7871.46 are vulnerable, as the issue resides in the Tint component of Chrome’s rendering engine.

Risk and Exploitability

Chromium assigns a CVSS score of 8.8, indicating high severity. The EPSS score is below 1%, suggesting that the likelihood of real‑world exploitation is very low at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description as a maliciously crafted HTML page delivered over the network; when the page is rendered, the out‑of‑bounds memory access is triggered. Successful exploitation could corrupt memory and lead to browser crashes, control memory content.

Generated by OpenCVE AI on July 21, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to obtain the fix.
  • Restart Chrome after installing the update so the new binaries are loaded.
  • Avoid visiting untrusted websites that may serve malicious HTML content.

Generated by OpenCVE AI on July 21, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Access in Chrome Tint Rendering Component

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Access in Chrome Tint Rendering Component

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read/Write in Chrome Tint Rendering Component

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read/Write in Chrome Tint Rendering Component

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome Tint Out‑of‑Bounds Memory Access

Sat, 11 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Tint Out‑of‑Bounds Memory Access

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Tint Out-of-Bounds Read/Write Vulnerability Enables Remote Memory Access

Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Tint Out-of-Bounds Read/Write Vulnerability Enables Remote Memory Access

Wed, 08 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read/Write in Chrome Rendering Engine Enables Remote Memory Access

Tue, 07 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read/Write in Chrome Rendering Engine Enables Remote Memory Access

Tue, 07 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome Tint out‑of‑bounds memory access via crafted HTML

Mon, 06 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Tint out‑of‑bounds memory access via crafted HTML

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Access in Chrome's Tint Rendering Component

Sun, 05 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Access in Chrome's Tint Rendering Component

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read/Write in Chrome’s Tint Rendering Engine

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read/Write in Chrome’s Tint Rendering Engine

Sat, 04 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read/Write in Google Chrome Tint Rendering Component

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read/Write in Google Chrome Tint Rendering Component

Fri, 03 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in Chrome's Tint Render Engine

Fri, 03 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in Chrome's Tint Render Engine

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chromium Tint Out‑Of-Bounds Memory Access Vulnerability
Weaknesses CWE-120

Thu, 02 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chromium Tint Out‑Of-Bounds Memory Access Vulnerability
Weaknesses CWE-120

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read/Write in Chrome's Tint Component
Weaknesses CWE-122
CWE-787

Thu, 02 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read/Write in Chrome's Tint Component
Weaknesses CWE-122
CWE-787

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T16:56:39.292Z

Reserved: 2026-07-01T21:37:33.552Z

Link: CVE-2026-14422

cve-icon Vulnrichment

Updated: 2026-07-02T16:43:18.380Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:00:04Z

Weaknesses