Description
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free vulnerability exists in the Views component of Google Chrome. If a user interacts with a specially crafted web page that requires specific UI gestures, the flaw can trigger heap corruption. The vulnerability is classified as CWE‑416. The CVSS score of 9.6 indicates critical severity, but the description only cites heap corruption as the consequence.

Affected Systems

Google Chrome desktop releases prior to version 150.0.7871.47 are affected. The vulnerability can be exploited when a user of these versions views malicious web content that triggers specific UI gestures.

Risk and Exploitability

The CVSS score of 9.6 signals critical severity, but the EPSS score of < 1% suggests exploitation is currently unlikely. The flaw is not listed in CISA’s KEV catalog. Attackers would need to deliver a maliciously crafted HTML page that forces a user to perform particular UI gestures to trigger the use‑after‑free. If successful, the resulting heap corruption could destabilize the browser or lead to further exploitation, but the potential for remote code execution is not confirmed in the current description.

Generated by OpenCVE AI on July 17, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later
  • Enable automatic updates for Chrome to receive security patches promptly
  • Avoid accessing unknown or suspicious web pages until the update is applied

Generated by OpenCVE AI on July 17, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Allowing Heap Corruption via UI Gestures

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Allowing Heap Corruption via UI Gestures

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Leading to Heap Corruption

Mon, 13 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Leading to Heap Corruption

Sun, 12 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Enables Heap Corruption via Crafted Web Page

Sat, 11 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Enables Heap Corruption via Crafted Web Page

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component

Thu, 09 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component

Wed, 08 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Leads to Heap Corruption

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Leads to Heap Corruption

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free Heap Corruption in Chrome Views Enables Remote Code Execution

Sun, 05 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free Heap Corruption in Chrome Views Enables Remote Code Execution

Sat, 04 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Allows Heap Corruption via Crafted HTML

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Allows Heap Corruption via Crafted HTML

Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Remote Code Execution via Crafted HTML Page

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Remote Code Execution via Crafted HTML Page

Thu, 02 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Free in Chrome Views

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Free in Chrome Views

Thu, 02 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enabling Potential Remote Code Execution

Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enabling Potential Remote Code Execution

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Potential Remote Code Execution

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Potential Remote Code Execution

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:22.071Z

Reserved: 2026-06-29T23:03:16.846Z

Link: CVE-2026-13784

cve-icon Vulnrichment

Updated: 2026-07-01T17:56:04.871Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:15:16Z

Weaknesses