Junglewise Threat Intelligence

CVE-2026-14094: Google Chrome use after free in Installer

CVE-2026-14094 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome installer for Windows. A local attacker could use a specially crafted file to gain higher-level system permissions. This could allow an unauthorized user to take control of the operating system or access restricted data.

Technical details

A use-after-free (UAF) vulnerability exists in the Installer component of Google Chrome for Windows (CWE-416). The flaw is triggered when the installer processes a malicious file, leading to memory corruption. A local attacker with limited privileges can exploit this condition to execute code with elevated OS-level permissions. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats