Junglewise Threat Intelligence

CVE-2026-14027: Google Chrome use after free in SignIn

CVE-2026-14027 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the sign-in component could allow a remote attacker to cause memory corruption if they can trick a user into performing specific interactions on a malicious website. This could potentially lead to browser instability or unauthorized access to information within the browser session.

Technical details

A use-after-free (UAF) vulnerability exists in the SignIn component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This sequence leads to the reuse of memory after it has been freed, potentially resulting in heap corruption. The vulnerability is classified as Low severity by Chromium and is addressed in version 150.0.7871.47. Exploitation requires user interaction and specific UI navigation.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats