Junglewise Threat Intelligence

CVE-2026-14040: Google Chrome use after free in BrowserTag

CVE-2026-14040 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's BrowserTag component could allow a malicious browser extension to cause memory corruption. If a user is tricked into installing a specially crafted extension, an attacker could potentially crash the browser or execute unauthorized actions. This issue is mitigated by the requirement for a user to manually install a malicious extension.

Technical details

A use-after-free (UAF) vulnerability exists in the BrowserTag component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when a user installs and runs a specifically crafted Chrome Extension designed to manipulate memory management within the BrowserTag logic. This can lead to heap corruption, potentially allowing for arbitrary code execution within the context of the browser process, though it is categorized as Low severity by the vendor. The attack requires the precondition of a user installing a malicious extension. Google has addressed this in the stable channel update to version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats