Junglewise Threat Intelligence

CVE-2026-14383: Google Chrome V8 inappropriate implementation code execution

CVE-2026-14383 · Severity: info · CVSS 6.5 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a remote attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website designed to exploit a flaw in how the browser processes JavaScript. While the attack is limited to the browser's security sandbox, it could lead to data theft or further system compromise if combined with other vulnerabilities.

Technical details

This vulnerability is classified as an 'Inappropriate implementation' within the V8 JavaScript engine of Google Chrome. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the browser's sandbox. The issue was addressed in Chrome version 150.0.7871.46 for Linux and 150.0.7871.46/.47 for Windows and Mac. Chromium developers have assigned this a 'Medium' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel.
  • 2026-07-01: disclosed: CVE published in NVD.

References

Related threats