Junglewise Threat Intelligence

CVE-2026-14107: Google Chrome use after free in Scheduling

CVE-2026-14107 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's scheduling component, which manages how the browser prioritizes and executes tasks. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code within the browser's security sandbox, potentially leading to further exploitation or instability of the application.

Technical details

A use-after-free (UAF) vulnerability exists in the Scheduling component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser improperly manages memory during task scheduling, allowing a remote attacker to leverage a crafted HTML page to reference memory after it has been freed. This can result in arbitrary code execution within the context of the browser's sandbox. The vulnerability is tracked as CWE-416 and was addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats