Junglewise Threat Intelligence

CVE-2026-14415: Google Chrome V8 heap corruption via UI gestures

CVE-2026-14415 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a vulnerability in its V8 JavaScript engine. If a user is tricked into visiting a malicious website and performing specific interactions, an attacker could potentially cause the browser to crash or execute unauthorized actions. This could impact the stability of the application and the security of the user's browsing session.

Technical details

An inappropriate implementation vulnerability exists in the V8 JavaScript engine within Google Chrome prior to version 150.0.7871.46. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This sequence can lead to heap corruption. While the Chromium project classifies this as Low severity, heap corruption vulnerabilities can sometimes be leveraged for memory exhaustion or arbitrary code execution within the browser's sandboxed process. The issue is resolved in version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop
  • 2026-07-01: advisory: NVD published the CVE record

References

Related threats