Junglewise Threat Intelligence

CVE-2026-14043: Google Chrome use after free in GetUserMedia

CVE-2026-14043 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's GetUserMedia component, which handles camera and microphone access. An attacker who has already compromised a browser's rendering process could use this flaw to escape the browser's security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the GetUserMedia component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during media stream processing. An attacker who has already achieved code execution within a compromised renderer process can exploit this condition via a specially crafted HTML page to perform a sandbox escape. This vulnerability is classified by Chromium as 'Low' severity, likely due to the precondition of a prior renderer compromise. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats