Junglewise Threat Intelligence

CVE-2026-14394: Google Chrome use after free in V8

CVE-2026-14394 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a malicious website to cause memory corruption on a user's computer. While rated as low severity, this could potentially lead to browser instability or crashes when visiting a specially crafted web page.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could result in a renderer process crash or potentially limited execution within the browser's sandbox. The issue is addressed in Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46/.47
  • 2026-07-01: disclosed: CVE published

References

Related threats