CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-14405

CVSS 9.6v3.1pub. 2026-07-01upd. 2026-07-03

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

🤖 AI Analysis
How it works

The flaw consists of the use of uninitialized memory (CWE-457, Uninitialized Use) in the V8 engine responsible for executing JavaScript code. An attacker can prepare a specially crafted HTML page whose processing by the V8 engine leads to reading or performing operations on uninitialized data in memory. As a result, arbitrary code execution is possible within the browser sandbox. User interaction is limited to visiting the attacker-controlled website.

Impact

An attacker can execute arbitrary code (RCE) in the context of the browser's rendering process, limited by the sandbox. In combination with a potential exploit enabling sandbox escape, the impact could include full system compromise.

Mitigation & patch

Google Chrome must be updated to version 150.0.7871.46 or later. The update is available through the browser's automatic update mechanism or according to information published on the Chrome Releases blog.

Who is affected

Google Chrome versions prior to 150.0.7871.46

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Google Chrome

    APP
    Google
    < 150.0.7871.46
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox