Junglewise Threat Intelligence

CVE-2026-14024: Google Chrome use after free in Ozone on Linux

CVE-2026-14024 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser for Linux. An attacker could create a malicious webpage that, when visited, tricks a user into performing specific mouse or keyboard actions to trigger a memory error. This could allow the attacker to crash the browser or potentially execute unauthorized code on the user's computer.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone component of Google Chrome for Linux. Ozone is the windowing system abstraction layer used by Chromium. The flaw is triggered when a remote attacker convinces a user to visit a specially crafted HTML page and perform specific UI gestures. This sequence leads to a use-after-free condition, which can result in heap corruption. An attacker could potentially leverage this to achieve arbitrary code execution within the browser's sandboxed process. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats