• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-14431: remote code execution in Google Chrome

Remote attackers can execute code inside the Chrome renderer sandbox by getting a user to load a specially crafted page; this is tracked as CVE-2026-14431. The flaw is a type confusion in V8 that affects Chrome 150.x releases before 150.0.7871.46 and is fixed in 150.0.7871.46. An attacker only needs to convince a user to visit a malicious or compromised web page (user interaction required).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00451
CWE
CWE-843
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize updating Chrome to 150.0.7871.46 or later immediately to remove the exposed V8 type confusion.

What is CVE-2026-14431?

Remote attackers can execute code inside the Chrome renderer sandbox by getting a user to load a specially crafted page; this is tracked as CVE-2026-14431. The flaw is a type confusion in V8 that affects Chrome 150.x releases before 150.0.7871.46 and is fixed in 150.0.7871.46. An attacker only needs to convince a user to visit a malicious or compromised web page (user interaction required).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
150.x150.0.7871.46 – before 150.0.7871.46150.0.7871.46

Is CVE-2026-14431 being exploited?

Public exploit code is available as of 2026-09-29.

How to fix CVE-2026-14431

  1. Apply the vendor update to Chrome 150.0.7871.46 or later on all affected endpoints.
  2. Block or limit access to untrusted web content and disable unnecessary web features where possible for high-risk users.
  3. Monitor endpoint telemetry for crashes or suspicious renderer activity and investigate users who visited untrusted pages.
  4. Follow Google’s release notes and guidance for any additional mitigation steps.

Frequently asked questions

Is CVE-2026-14431 being actively exploited?

Public exploit code is available as of 2026-09-29, indicating a higher risk of active exploitation.

Which Chrome versions are affected by CVE-2026-14431?

Chrome 150.x releases prior to 150.0.7871.46 are affected; the issue is fixed in 150.0.7871.46.

Is there a patch for CVE-2026-14431?

Yes. Google fixed the vulnerability in Chrome version 150.0.7871.46; update affected installations to that version or later.

Does CVE-2026-14431 require authentication?

No authentication is required, but the exploit requires user interaction: a victim must load a malicious web page in Chrome.

References