Junglewise Threat Intelligence

CVE-2026-14025: Google Chrome use after free in Views on macOS

CVE-2026-14025 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for macOS that could allow a malicious website to cause memory corruption. To trigger the issue, an attacker must trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard interactions. If successful, this could lead to browser instability or potentially allow the attacker to execute unauthorized actions within the context of the browser.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' UI framework component of Google Chrome for macOS. The flaw is triggered when a remote attacker convinces a user to visit a malicious HTML page and engage in specific UI gestures, leading to heap corruption. This is classified as CWE-416. The vulnerability was addressed in Chrome version 150.0.7871.47 for Mac. While UAF bugs can often lead to arbitrary code execution, Chromium developers have rated this specific instance as Low severity, likely due to the high degree of user interaction required.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats