CVE-2026-14431Disclosure(google / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-07-01); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-04: 1Mentions · 2026-07-17: 1Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-17: 1Exploit Tool / Code · 2026-07-17: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-24: 107-0107-0207-0407-1707-24
Signal classification4 categories
Disclosure
240.0%
Patch
120.0%
Exploit
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-021
Disclosure1
2026-07-041
Patch1
2026-07-171
Exploit1
2026-07-241
General1
Full discourse5 posts
  • itszn@itszn13
    Disclosure

    We found another exploitable V8 JIT bug CVE-2026-14431; fixed in the most recent Chrome update This one was an interesting case of sloppy mode breaking JIT assumptions In addition the same session was able to find a working v8 heap sandbox bypass (although it ended up as a dup) https://t.co/FTL3Z86cAs

    Post summary

    A new V8 JIT flaw (CVE-2026-14431) has been disclosed, including a PoC and sandbox bypass details, and is already fixed in the latest Chrome release.

    62722909524.1K
    11.2K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-14431 PT ID: PT-2026-54698 Vendor: Google Product: Chrome Description: Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-54698 • https://github.com/jaf0rk/CVE-2026-14431 #dbugs_vuln

    Post summary

    A PoC and functional exploit for CVE-2026-14431 are available via a GitHub repository, but there is no evidence of active exploitation or a patch.

    02023104.3K
    3.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-14431 (CVSS 8.8) Type confusion in V8 allows remote code execution in Chrome <150.0.7871.46 via crafted HTML. Update immediately. #CVE #PatchNow #ThreatIntel https://t.co/7x7QnuwJJc

    Post summary

    This tweet announces a high‑CVSS vulnerability (CVE‑2026‑14431) affecting Chrome, explains the technical flaw, and calls for immediate patching.

    0000178
    58 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-14431 Type Confusion in V8 in Google Chrome Prior to 150.0.7871.46 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14431

    Post summary

    The post cites CVE-2026-14431, detailing a type‑confusion flaw in V8 affecting Chrome versions before 150.0.7871.46, but offers no PoC, exploit, or mitigation information.

    00001130
    4.1K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-14431: Type Confusion in Google Chrome V8 - What It Means for Your Business and How to Respond https://hubs.ly/Q04qLFP90

    Post summary

    The brief title references CVE‑2026‑14431, a type‑confusion issue in Chrome V8, but provides no proof‑of‑concept, exploit code, or evidence of active exploitation; it hints at mitigation but does not specify a patch.

    0000044
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more