Junglewise Threat Intelligence

CVE-2026-14431: Google Chrome type confusion in V8

CVE-2026-14431 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the exploit is contained within the browser's security sandbox, it represents a significant risk to system integrity and user data privacy.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types, which can be exploited by a remote attacker through a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the Chromium renderer process sandbox. This issue was addressed in Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 151 promoted to stable channel containing fixes for version 150.
  • 2026-07-01: disclosed: CVE record published.

References

Related threats