Executive brief
A vulnerability in Google Chrome's V8 engine could allow a remote attacker to execute unauthorized code within the browser's security sandbox. This occurs when a user visits a specially crafted website. While the impact is limited by the browser's sandbox, it represents a potential security risk for users on older versions of the browser.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to use a variable that has not been properly initialized, which can be induced by a remote attacker through a specifically crafted HTML page. Successful exploitation allows for arbitrary code execution within the constraints of the Chrome renderer sandbox. The vulnerability was addressed in Chrome version 150.0.7871.46. Google classified this issue with a 'Low' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
- 2026-07-01: disclosed: CVE-2026-14405 published