DIRAS TAKE
Urgent: public exploit code exists, so prioritize updating Chrome to 150.0.7871.46 or later immediately to remove the exposed V8 type confusion.
What is CVE-2026-14431?
Remote attackers can execute code inside the Chrome renderer sandbox by getting a user to load a specially crafted page; this is tracked as CVE-2026-14431. The flaw is a type confusion in V8 that affects Chrome 150.x releases before 150.0.7871.46 and is fixed in 150.0.7871.46. An attacker only needs to convince a user to visit a malicious or compromised web page (user interaction required).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 150.x | 150.0.7871.46 – before 150.0.7871.46 | 150.0.7871.46 |
Is CVE-2026-14431 being exploited?
Public exploit code is available as of 2026-09-29.
How to fix CVE-2026-14431
- Apply the vendor update to Chrome 150.0.7871.46 or later on all affected endpoints.
- Block or limit access to untrusted web content and disable unnecessary web features where possible for high-risk users.
- Monitor endpoint telemetry for crashes or suspicious renderer activity and investigate users who visited untrusted pages.
- Follow Google’s release notes and guidance for any additional mitigation steps.
Frequently asked questions
Is CVE-2026-14431 being actively exploited?
Public exploit code is available as of 2026-09-29, indicating a higher risk of active exploitation.
Which Chrome versions are affected by CVE-2026-14431?
Chrome 150.x releases prior to 150.0.7871.46 are affected; the issue is fixed in 150.0.7871.46.
Is there a patch for CVE-2026-14431?
Yes. Google fixed the vulnerability in Chrome version 150.0.7871.46; update affected installations to that version or later.
Does CVE-2026-14431 require authentication?
No authentication is required, but the exploit requires user interaction: a victim must load a malicious web page in Chrome.
References
- nvd.nist.gov/vuln/detail/CVE-2026-14431
- cve.org/CVERecord?id=CVE-2026-14431
- chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
- issues.chromium.org/issues/523884658
- All Google CVEs on CVE Radar
- CVEs published in September 2026