Junglewise Threat Intelligence

CVE-2026-14009: Google Chrome heap corruption in Passwords

CVE-2026-14009 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the password management component of Google Chrome, a widely used web browser. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially leading to a browser crash or unauthorized memory access. This could impact the stability of the application and the security of user data handled by the browser.

Technical details

This vulnerability is classified as an inappropriate implementation within the Passwords component of Google Chrome. The flaw allows for potential heap corruption when the browser processes a specially crafted HTML page. An attacker can exploit this by hosting a malicious website and enticing a user to visit it (remote, no authentication required). Successful exploitation could lead to memory corruption, potentially allowing for arbitrary code execution or a denial-of-service condition within the browser process. The issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats