Junglewise Threat Intelligence

CVE-2026-14006: Google Chrome use after free in Navigation

CVE-2026-14006 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, is affected by a security vulnerability in its navigation component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. This could lead to the theft of sensitive information, unauthorized access to accounts, or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Navigation component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during page navigation processes. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation could lead to arbitrary code execution (ACE) within the context of the browser process. Google has addressed this issue in the stable channel update 150.0.7871.47 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Google Chrome release announcement published
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats