Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14156

CVE-2026-14156: Google Chrome Auth Bypass Vulnerability

CVE-2026-14156 is an authentication bypass flaw in Google Chrome's StorageAccessAPI that allows attackers to bypass same origin policy. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-14156 Overview

CVE-2026-14156 is a same-origin policy bypass in the StorageAccessAPI component of Google Chrome. The vulnerability stems from insufficient policy enforcement in Chrome versions prior to 150.0.7871.47. A remote attacker who has already compromised the renderer process can leverage a crafted HTML page to bypass same-origin restrictions. The flaw is tracked under [CWE-862] Missing Authorization and [CWE-284] Improper Access Control. Chromium classifies the internal severity as Low, while the NVD assigns a medium CVSS rating driven by high integrity impact. Successful exploitation allows cross-origin data manipulation from within a compromised renderer sandbox.

Critical Impact

An attacker who controls a compromised renderer process can bypass the same-origin policy through a crafted HTML page, enabling cross-origin integrity violations against otherwise isolated web contexts.

Affected Products

  • Google Chrome versions prior to 150.0.7871.47
  • Chromium-based browsers sharing the vulnerable StorageAccessAPI implementation
  • Desktop Stable channel builds on Windows, macOS, and Linux

Discovery Timeline

  • 2026-06-30 - CVE-2026-14156 published to NVD
  • 2026-07-02 - Last updated in NVD database

Technical Details for CVE-2026-14156

Vulnerability Analysis

The vulnerability resides in Chrome's StorageAccessAPI, the browser interface that governs whether embedded contexts may access unpartitioned cookies and storage. Chrome enforces same-origin restrictions to keep documents from different origins isolated. Insufficient policy enforcement within StorageAccessAPI breaks that guarantee under specific conditions. An attacker who has already achieved renderer compromise can invoke the API through a crafted HTML page and reach storage or state that belongs to another origin. The impact is scoped to integrity — the attacker can influence or manipulate cross-origin data — but the NVD vector reports no direct confidentiality or availability impact. User interaction is required, consistent with loading attacker-controlled content in the browser.

Root Cause

The root cause is a missing authorization check ([CWE-862]) combined with improper access control ([CWE-284]) inside the StorageAccessAPI policy layer. The API fails to fully validate that the requesting context is entitled to operate on the target origin before granting access, allowing a malicious renderer to reach across the origin boundary.

Attack Vector

Exploitation follows a chained model. The attacker must first compromise the renderer process, typically through a separate memory corruption or logic bug delivered by a malicious site. From that foothold, the attacker serves a crafted HTML page that interacts with StorageAccessAPI in a way that bypasses the same-origin policy. The attack is network-reachable and requires user interaction to visit or interact with the attacker's page. See the Chromium Issue Tracker Entry for implementation-specific technical details.

No verified public proof-of-concept is available for CVE-2026-14156.
Refer to the Chromium issue tracker for reproduction details once access is granted.

Detection Methods for CVE-2026-14156

Indicators of Compromise

  • Chrome browser processes running versions earlier than 150.0.7871.47 on managed endpoints.
  • Renderer processes exhibiting unexpected crashes or anomalous child process behavior before navigation to unfamiliar domains.
  • Outbound connections from browser sessions to low-reputation domains hosting scripted StorageAccessAPI invocations.

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag hosts running builds below 150.0.7871.47.
  • Correlate browser telemetry with endpoint logs to identify renderer compromise indicators such as unusual sandbox escapes or code injection attempts.
  • Monitor web proxy logs for pages that request document.requestStorageAccess() in combination with cross-origin frame activity from unknown domains.

Monitoring Recommendations

  • Enable browser enterprise reporting to collect version and extension telemetry centrally.
  • Alert on Chrome crash reports referencing blink::StorageAccessHandle or related storage access components.
  • Track patch compliance through configuration management and generate alerts when endpoints fall behind the current Stable channel release.

How to Mitigate CVE-2026-14156

Immediate Actions Required

  • Update Google Chrome to version 150.0.7871.47 or later on all Windows, macOS, and Linux endpoints.
  • Restart Chrome after the update to ensure the patched binaries are loaded into active user sessions.
  • Audit and update Chromium-based browsers and embedded WebViews that share the vulnerable code path.

Patch Information

Google released the fix in the Stable channel update documented at the Google Chrome Update Blog. The corrective change is tracked in the Chromium Issue Tracker Entry. Apply version 150.0.7871.47 or later to remediate the same-origin policy bypass.

Workarounds

  • Enforce automatic browser updates through enterprise policy so users cannot defer the patch.
  • Restrict browsing to trusted sites via URL allowlists where feasible, since exploitation requires loading a crafted page.
  • Deploy site isolation and strict third-party cookie settings to reduce the value of a successful StorageAccessAPI bypass.
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Windows: query installed version from the registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# macOS: read the bundle version
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.