Junglewise Threat Intelligence

CVE-2026-14067: Google Chrome for iOS use after free in HTML processing

CVE-2026-14067 · Severity: info · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS, a popular mobile web browser, is affected by a security vulnerability that could allow a malicious website to execute unauthorized code on a user's device. By tricking a user into visiting a specially crafted webpage, an attacker could potentially compromise the application. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in Google Chrome for iOS (CWE-416). The flaw is triggered when the browser improperly manages memory during the processing of HTML content. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation could lead to arbitrary code execution within the context of the browser process, though Chromium has rated the severity as Low. The issue is resolved in version 150.0.7871.47.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats