Junglewise Threat Intelligence

CVE-2026-14119: Google Chrome type confusion in Bluetooth

CVE-2026-14119 · Severity: info · CVSS 3.1 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Bluetooth component on Windows could allow a malicious device nearby to access sensitive information from the browser's memory. This occurs when the browser incorrectly handles data from a malicious Bluetooth peripheral. While the risk is localized to the user's physical vicinity, it could lead to the exposure of private data handled by the browser.

Technical details

A type confusion vulnerability (CWE-843) exists in the Bluetooth implementation of Google Chrome on Windows. The flaw is triggered when the browser interacts with a malicious Bluetooth peripheral on the local network segment (adjacent attack vector). By providing unexpected data types that the browser fails to validate correctly, an attacker can cause the application to access memory using an incompatible type. This can be leveraged to leak sensitive information from the Chrome process memory. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats