CVE-2026-14395
published 2026-07-01CVE-2026-14395: Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.26%
18.3th percentile
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.46 | 150.0.7871.46 | |
| chrome | >= 150.0.7871.46 < 150.0.7871.46 | 150.0.7871.46 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-14395
vendor_chrome·2026-07-16
CVE-2026-14395 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-14395
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-14395
Red Hat
chromium-browser: chromium-browser: Out of bounds write in V8
vendor_redhat·2026-06-30·CVSS 8.8
CVE-2026-14395 [HIGH] CWE-787 chromium-browser: chromium-browser: Out of bounds write in V8
chromium-browser: chromium-browser: Out of bounds write in V8
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=511290389
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ghsa_unreviewed·2026-07-02
CVE-2026-14395 [HIGH] CWE-787 Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
2026-07-01
Published