All findings

CVE-2026-14431 high

Chrome directly credits Codex Security on V8 type-confusion CVE

Chrome 150 directly credits OpenAI Codex Security on CVE-2026-14431, a High-severity V8 type confusion published in June 2026.

Bug class
Type confusion
Affected codebase
Google Chrome V8
Credited system
OpenAI Aardvark / Codex Security
Also credited
OpenAI Daybreak
Disclosed
June 30, 2026
Attribution
Direct source attribution
Severity
high
Source status: Chrome 150 directly credits OpenAI Codex Security (amyb) on CVE-2026-14431 and rates it High. CVE-2026-9973 is kept in a separate Daybreak entry because Chrome names only OpenAI, not Codex Security, on that issue.

Summary

CVE-2026-14431 is a V8 type confusion rated High by Chrome. It is one publicly identifiable part of OpenAI’s broader statement that its researchers reported five exploitable V8 bugs.

Attribution

The Chrome release note directly names OpenAI Codex Security on this CVE. The separate CVE-2026-9973 entry preserves Chrome’s less specific “amyb of OpenAI” credit without extending Codex attribution beyond the source.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.