Junglewise Threat Intelligence

CVE-2026-14032: Google Chrome use after free in Bluetooth on Mac

CVE-2026-14032 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for macOS could allow a malicious browser extension to execute unauthorized code on a user's computer. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. If successful, this could lead to a full compromise of the user's browser environment and potentially the underlying operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the Bluetooth component of Google Chrome on macOS. The flaw is triggered when the browser incorrectly manages memory lifecycle for Bluetooth-related objects, allowing a malicious Chrome Extension to reference memory after it has been freed. An attacker who successfully convinces a user to install a crafted extension can leverage this memory corruption to achieve arbitrary code execution within the context of the browser. This issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats