Junglewise Threat Intelligence

CVE-2026-14111: Google Chrome use after free in WebProtect

CVE-2026-14111 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's WebProtect component that could allow a malicious browser extension to execute unauthorized code. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. If successful, this could lead to a compromise of the user's browser session and potentially their local system.

Technical details

A use-after-free (UAF) vulnerability exists in the WebProtect component of Google Chrome prior to version 150.0.7871.47. The flaw is categorized as CWE-416 and is triggered when the browser improperly handles memory objects after they have been freed. An attacker can exploit this by convincing a user to install a malicious Chrome Extension designed to trigger the memory corruption. Successful exploitation allows for arbitrary code execution within the context of the browser. Google has addressed this issue in the stable channel update 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats