Junglewise Threat Intelligence

CVE-2026-14430: Google Chrome integer overflow in V8

CVE-2026-14430 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, was found to have a security vulnerability in its V8 JavaScript engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's device. While the exploit is limited to the browser's security sandbox, it represents a significant risk to user data and system integrity.

Technical details

An integer overflow vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious website and enticing a user to visit it. Successful exploitation allows for arbitrary code execution within the browser's sandbox environment. This issue was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop.
  • 2026-07-01: advisory: NVD published the CVE record.

References

Related threats