Junglewise Threat Intelligence

CVE-2026-14424: Google Chrome use after free in Dawn on macOS

CVE-2026-14424 · Severity: info · CVSS 8.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical safety feature designed to prevent malicious code from escaping the browser and accessing the rest of your computer. If exploited, an attacker could potentially gain unauthorized access to your system or data simply by convincing you to visit a specially crafted webpage.

Technical details

A use-after-free (UAF) vulnerability exists in Dawn, the WebGPU implementation in Google Chrome, specifically affecting the macOS platform. The flaw is triggered when the browser incorrectly manages memory during the processing of web content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code and escape the Chrome renderer sandbox. This vulnerability was addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.46/.47 for Windows and Mac.
  • 2026-07-01: disclosed: CVE published to NVD.

References

Related threats