CVE-2026-14432Disclosure(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-07-02); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-07-02: 4Mentions · 2026-07-04: 1Mentions · 2026-07-12: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-02: 3Technical Details · 2026-07-04: 1Technical Details · 2026-07-12: 107-0207-0407-12
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-024
Disclosure4
2026-07-041
Patch1
2026-07-121
Patch1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-14432 Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium s… https://www.cve.org/CVERecord?id=CVE-2026-14432

    Post summary

    CVE‑2026‑14432 is a use‑after‑free vulnerability in V8 affecting Chrome versions before 150.0.7871.46, allowing an attacker to execute arbitrary code inside a sandbox using a crafted HTML page; no PoC, exploit code, active exploitation, or patches are reported.

    00011814
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-14432 (CVSS 8.8) - Use-after-free in Google Chrome V8 engine (versions < 150.0.7871.46) enables remote code execution via crafted HTML. Update Chrome immediately. #CVE #PatchNow https://t.co/O65zXAQ2j0

    Post summary

    A high‑severity use‑after‑free vulnerability in Google Chrome’s V8 engine (CVE‑2026‑14432) enables remote code execution; users should update Chrome immediately to apply the patch.

    0000164
    58 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-14432) https://vuldb.com/vuln/375779

    Post summary

    The post announces that the severity rating for the newly identified Google Chrome vulnerability CVE-2026-14432 has been increased, with no additional details on exploitation or remediation.

    00001125
    2.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-14432 Remote Code Execution via Use After Free in Google Chrome Prior to 150.0.7871.46 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14432

    Post summary

    The post announces CVE‑2026‑14432, a Remote Code Execution vulnerability in Google Chrome caused by a Use After Free bug affecting versions prior to 150.0.7871.46, without mentioning PoC, exploit code, or remediation.

    00001131
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14432 Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium s… https://www.cve.org/CVERecord?id=CVE-2026-14432 ----- Traducción: CVE-2026-14432 Use… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-14432, a use‑after‑free vulnerability in Chrome’s V8 engine that enables arbitrary code execution through a crafted HTML page. No proof of concept, exploit code, or patch information is provided.

    0000155
    91 followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ Chrome’s sandbox isn’t a force field: CVE-2026-14432 lets crafted HTML trigger V8’s use-after-free and run code inside it. Update to 150.0.7871.46+, then relaunch. https://windowsforum.com/threads/cve-2026-14432-fixed-in-chrome-150-0-7871-46-update-now.437215/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #V8Vulnerability #ChromeSecurity #GoogleChrome #Cve202614432 https://t.co/rBP00kNee6

    Post summary

    The post highlights a use‑after‑free vulnerability in Chrome’s V8 engine (CVE‑2026‑14432) and recommends updating to version 150.0.7871.46+ to mitigate the risk.

    0000081
    1.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more