Junglewise Threat Intelligence

CVE-2026-14010: Google Chrome uninitialized use in Codecs

CVE-2026-14010 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a remote attacker to access sensitive information from the computer's memory. This occurs when the browser processes specially crafted media content on a website. An attacker could exploit this by tricking a user into visiting a malicious webpage, potentially leading to the exposure of private data from other open tabs or browser processes.

Technical details

An uninitialized use vulnerability (CWE-457) exists within the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser processes media content via a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to an information disclosure where sensitive data is read from uninitialized process memory. This vulnerability was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats