CVE-2026-14431 is a high-severity type confusion vulnerability in the V8 JavaScript engine used by Google Chrome. In Google Chrome versions prior to 150.0.7871.46, improper handling of object types in V8 could allow a remote attacker to trigger memory corruption by causing the engine to operate on an object with an unexpected type. The issue is reachable through web content and can be triggered via a crafted HTML page, potentially resulting in arbitrary code execution within the Chrome renderer sandbox.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone V8 exploit repository containing a README and one JavaScript exploit file, exp.js. It targets CVE-2026-14431, described via the linked V8 Maglev fix 'Check map of inlined array in ArrayIteratorPrototypeNext'. The exploit is intended to run locally in the V8 d8 shell with native syntax enabled, not as a remote network exploit. Repository structure is minimal: README.md documents the vulnerable environment, exact V8 version (14.9.207.29), Linux/x64 build assumptions, and execution instructions; exp.js contains the full exploit logic. The code warms up two code paths (tagged and double arrays) to encourage Maglev/JIT optimization, then flips a transition flag so helper functions mutate array element kinds during iterator access. This creates a type/map confusion condition that is used to reinterpret values and derive exploitation primitives. Core capabilities in exp.js: - Utility conversions between float64 and 64-bit integers using ArrayBuffer typed arrays. - JIT-triggered confusion primitives via tagged_outer()/double_outer() and reflective argument mutation using eval on function arguments. - addrof(obj): leaks a compressed address-like value for a JavaScript object. - get_fake_obj(addr): forges a fake object by hardcoding a stable map pointer and properties field for the target V8 build. - cage_read(addr) / cage_write(addr, value): arbitrary read/write primitives within the V8 sandbox cage. The exploit is operational as a sandboxed primitive generator, but it does not include a sandbox escape or full code execution chain. The README explicitly states that only read/write primitives inside the V8 sandbox are currently achieved and that sandbox escape research is still pending. The script ends with %DebugPrint on crafted objects and %SystemBreak(), indicating it is meant for exploit development and debugging rather than turnkey compromise.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.