Junglewise Threat Intelligence

CVE-2026-14005: Google Chrome use after free in Omnibox

CVE-2026-14005 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the Omnibox (address bar) of Google Chrome for Android. If a user is tricked into visiting a malicious website and performing specific touch gestures, an attacker could potentially crash the browser or execute unauthorized code. This could lead to the compromise of user data or the stability of the application.

Technical details

A use-after-free (UAF) vulnerability exists in the Omnibox component of Google Chrome for Android prior to version 150.0.7871.47. The flaw is triggered when a remote attacker convinces a user to visit a specially crafted HTML page and perform specific UI gestures. This sequence of events leads to the reuse of previously freed memory, resulting in heap corruption. An attacker could leverage this to achieve arbitrary code execution within the context of the browser process. The vulnerability is tracked as CWE-416. Google has released version 150.0.7871.47 to address this issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats