Skip to content
GoogleCVE-2026-14407

Google Chrome: remote code execution

High8.8CVE-2026-14407 · Published Jul 1, 2026 · updated Jul 3, 2026

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 150.0.7871.46, < 150.0.7871.46150.0.7871.46
Details and references

More Google advisories

All Google
Advisory
Google Chrome: use after free
Critical9.6Jul 1
Google Chrome: use after free
High7.5Jul 1
Google Chrome: buffer overflow
High8.3Jul 1
Google Chrome: improper input validation
High8.3Jul 1
Google Chrome: improper input validation
High8.3Jul 1
Google Chrome: integer overflow
High8.8Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.