Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14000

CVE-2026-14000: Google Chrome XSS Vulnerability

CVE-2026-14000 is a cross-site scripting flaw in Google Chrome's XML implementation that enables attackers to inject malicious scripts via crafted HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-14000 Overview

CVE-2026-14000 is a Universal Cross-Site Scripting (UXSS) vulnerability in the XML component of Google Chrome. The flaw stems from an inappropriate implementation that allows a remote attacker to inject arbitrary scripts or HTML through a crafted HTML page. Successful exploitation requires user interaction, such as visiting a malicious webpage. The issue affects Chrome versions prior to 150.0.7871.47 and is tracked under [CWE-79] (Improper Neutralization of Input During Web Page Generation). Chromium's security team rated the underlying issue as Medium severity.

Critical Impact

A remote attacker can bypass the same-origin policy and execute scripts in the context of arbitrary origins, enabling session hijacking, credential theft, and unauthorized actions on behalf of the victim.

Affected Products

  • Google Chrome versions prior to 150.0.7871.47
  • Chromium-based browsers incorporating the vulnerable XML component
  • Desktop stable channel builds across Windows, macOS, and Linux

Discovery Timeline

  • 2026-06-30 - CVE-2026-14000 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-14000

Vulnerability Analysis

The vulnerability resides in Chrome's XML handling code path. Chrome parses and renders XML documents, including XSLT-transformed content, and the affected implementation fails to correctly enforce output neutralization when generating HTML from XML input. An attacker who controls the content of an XML document served to the browser can cause script or HTML markup to be injected into the resulting rendered page. Because the injected content executes in the security context of the loaded document, the flaw qualifies as Universal Cross-Site Scripting (UXSS).

UXSS bugs are notable because they operate at the browser layer rather than a single web application. An attacker does not need to find an XSS flaw in a targeted site. Instead, the browser itself becomes the injection vector, allowing script execution against origins the attacker would otherwise be unable to compromise.

Root Cause

The root cause is improper output encoding or DOM construction within Chrome's XML rendering pipeline. When XML input is transformed into HTML for display, untrusted markup is not consistently sanitized before being incorporated into the document. This aligns with [CWE-79], where user-controlled data influences page generation without adequate neutralization.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker hosts a crafted HTML page that references or embeds malicious XML content. When a victim using an unpatched Chrome build visits the page, the XML parser processes the payload and injects attacker-controlled scripts or HTML into the rendered document. The scope is changed, meaning script execution can affect origins beyond the attacker's own. No verified public proof-of-concept code was available at the time of publication. Refer to the Chromium Issue Tracker Entry for technical details.

Detection Methods for CVE-2026-14000

Indicators of Compromise

  • Browser telemetry showing Chrome versions below 150.0.7871.47 loading external XML documents from untrusted origins
  • Unexpected script execution or DOM modifications on pages that embed or reference remote XML or XSL resources
  • Outbound connections from browser processes to newly registered or low-reputation domains immediately after XML content is rendered

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag hosts running builds prior to 150.0.7871.47
  • Monitor proxy and DNS logs for requests to attacker-controlled domains delivering Content-Type: application/xml or text/xml responses to browser user agents
  • Correlate browser process activity with subsequent credential submission or cookie exfiltration behavior to identify successful UXSS-driven session theft

Monitoring Recommendations

  • Ingest endpoint browser version telemetry into a centralized data lake to maintain continuous exposure visibility
  • Track child process spawning and file write activity from chrome.exe following visits to untrusted URLs
  • Alert on anomalous authentication events that follow browser sessions on unpatched hosts, which may indicate UXSS-assisted account takeover

How to Mitigate CVE-2026-14000

Immediate Actions Required

  • Update Google Chrome to version 150.0.7871.47 or later on all managed endpoints
  • Restart browser sessions after the update to ensure the vulnerable renderer processes are terminated
  • Audit Chromium-derived browsers in the environment and apply their vendor updates that incorporate the upstream fix

Patch Information

Google addressed CVE-2026-14000 in Chrome stable channel release 150.0.7871.47. Details are published in the Google Chrome Stable Update advisory. Administrators should enforce Chrome auto-update policies and validate that endpoints have completed the browser restart required to activate the patched binaries.

Workarounds

  • Enforce browser update policies through group policy or MDM to eliminate delay between patch release and deployment
  • Restrict access to untrusted websites via web filtering or DNS-layer controls until patching completes
  • Advise users to avoid clicking unsolicited links and to close unused tabs that render third-party XML content
bash
# Configuration example: verify Chrome version on Linux endpoints
google-chrome --version

# Windows: query installed Chrome version via registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.