Description
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Views component of Google Chrome allows a remote attacker to trigger heap corruption by presenting the user with a crafted HTML page that requires specific UI gestures. Classified under CWE‑416, this flaw could enable memory corruption within the browser process, which may be leveraged to execute arbitrary code and compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

All installations of Google Chrome older than version 150.0.7871.47 on any operating system (Windows, macOS, Linux, etc.) are potentially vulnerable. No specific platform restrictions were noted; the vulnerability applies to every platform that ships these Chrome releases.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity, while the EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA's KEV catalog, and a successful attack would require a victim to access a malicious web page and perform specific UI gestures; if achieved, the attacker could cause heap corruption in the browser process and potentially exploit it to execute arbitrary code.

Generated by OpenCVE AI on July 21, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Chrome update to version 150.0.7871.47 or newer.
  • Enable automatic updates so future security patches are applied without user action.
  • Avoid interacting with malicious web pages that trigger UI gestures or otherwise exploit this vulnerability.

Generated by OpenCVE AI on July 21, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Use-After-Free in Chrome Views Component

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Use-After-Free in Chrome Views Component

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Use‑After‑Free in Chrome Views

Mon, 13 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Heap Corruption via Use‑After‑Free in Chrome Views

Sat, 11 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Views Component Allows Heap Corruption via UI Gestures in Chrome

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Views Component Allows Heap Corruption via UI Gestures in Chrome

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption in Google Chrome Views Component

Tue, 07 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption in Google Chrome Views Component

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption via UI Gestures in Google Chrome

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption via UI Gestures in Google Chrome

Sun, 05 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Views Use‑After‑Free Exploitation via Crafted HTML

Sun, 05 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Chrome Views Use‑After‑Free Exploitation via Crafted HTML

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption in Chrome Views

Sat, 04 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption in Chrome Views

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Allows Heap Corruption via Crafted HTML

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Allows Heap Corruption via Crafted HTML

Thu, 02 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free Heap Corruption via UI Gestures in Google Chrome

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free Heap Corruption via UI Gestures in Google Chrome

Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Leading to Heap Corruption

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Leading to Heap Corruption

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome Views Use‑After‑Free Heap Corruption

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome Views Use‑After‑Free Heap Corruption

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:45.427Z

Reserved: 2026-06-29T23:03:24.241Z

Link: CVE-2026-13814

cve-icon Vulnrichment

Updated: 2026-07-01T15:11:47.699Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:30:09Z

Weaknesses