Junglewise Threat Intelligence

CVE-2026-14091: Google Chrome use after free in DevTools

CVE-2026-14091 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's DevTools, a set of web developer tools built directly into the browser. A remote attacker could potentially execute unauthorized code on a user's computer if the user visits a specially crafted website. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized actions within the browser environment.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the DevTools component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability is addressed in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats