Junglewise Threat Intelligence

CVE-2026-14419: Google Chrome use after free in Skia

CVE-2026-14419 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's Skia graphics engine. By tricking a user into visiting a specially crafted website, an attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the Skia graphics library as integrated into Google Chrome. The flaw is triggered when the browser improperly manages memory during the rendering of specially crafted HTML content. A remote, unauthenticated attacker can exploit this condition to execute arbitrary code outside of the Chrome renderer sandbox (sandbox escape). The vulnerability affects Google Chrome versions prior to 150.0.7871.46. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fix released in Chrome 150.0.7871.46/.47
  • 2026-07-01: advisory: NVD publication date

References

Related threats