CVE-2026-14416 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low). EPSS estimates a 0.22% chance of exploitation in the next 30 days.

## Description

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

## Metrics

CVSS 3.19.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Probability 0.22%

12.9th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-125](https://cwe.mitre.org/data/definitions/125.html)

## Affected Software

| Vendor | Product | Versions |
| --- | --- | --- |
| Google | Chrome | < 150.0.7871.46 |

## References

- [Release Notes, Vendor Advisory](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html)

- [Permissions Required](https://issues.chromium.org/issues/515428315)

## Timeline

Published Jul 1, 2026

Last Modified Jul 3, 2026

Status Analyzed

## Frequently Asked Questions

### What is CVE-2026-14416?

### How severe is CVE-2026-14416?

CVE-2026-14416 has a CVSS score of 9.6/10 (CRITICAL severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.

### How do I fix CVE-2026-14416?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

## How Strix Helps

- [How Strix found a critical auth bypass in etcd Strix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.](/content/blog/where-others-missed-it-etcd-auth-bypass/index.html)
- [Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.](/content/features/autonomous-pentesting/index.html)
- [PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.](/content/features/pr-reviews/index.html)
- [AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.](/content/ai-penetration-testing/index.html)
