Junglewise Threat Intelligence

CVE-2026-14064: Google Chrome for Android use after free in PageInfo

CVE-2026-14064 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a popular mobile web browser. A security vulnerability in the 'PageInfo' component—which displays site security and permission details—could allow a remote attacker to execute malicious code on a user's device. To succeed, an attacker would need to trick a user into visiting a specially crafted website and performing specific touch gestures or interactions within the browser interface.

Technical details

A use-after-free (UAF) vulnerability exists in the PageInfo component of Google Chrome for Android prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the display or interaction with site information metadata. A remote attacker can exploit this by hosting a malicious HTML page and convincing a user to perform specific UI gestures, leading to memory corruption. This could potentially result in arbitrary code execution within the context of the browser process. The vulnerability is tracked as CWE-416 and was assigned a 'Low' severity rating by Chromium developers.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats