Description
Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free vulnerability in the Omnibox component of Google Chrome on Android allows a remote attacker who convinces a user to perform specific UI gestures on a crafted HTML page to trigger heap corruption. This flaw can destabilize the browser or potentially lead to device compromise; however, the advisory does not explicitly state a denial of service or full compromise scenario. Based on the description, it is inferred that the heap corruption could destabilize the browser or might lead to device compromise, though this is not explicitly confirmed.

Affected Systems

Chrome for Android versions earlier than 150.0.7871.47 are affected; newer builds contain the update that fixes the use‑after‑free flaw.

Risk and Exploitability

CVSS score of 8.8 indicates high severity, while EPSS <1% suggests a very low but non‑zero exploitation probability. Attack requires the user to open a crafted page and execute particular Omnibox gestures, meaning the vector is user interaction. The advisory states the flaw is not listed in CISA’s KEV catalog. No confirmed remote code execution path is provided, so further compromise is not asserted. Based on the available evidence, exploitation remains constrained to the conditions described above.

Generated by OpenCVE AI on July 17, 2026 at 14:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 150.0.7871.47 or later to apply the fix for the use‑after‑free vulnerability.
  • If the latest update is not yet available, advise users to avoid interacting with URLs that may trigger Omnibox gestures and consider disabling Omnibox or using a minimal UI.
  • Enable Chrome’s Safe Browsing and Site Isolation features to limit the impact of untrusted content while waiting for the official patch.
  • For managed environments, enforce an automatic update policy or restrict access to the affected browser versions until the vulnerability is mitigated.

Generated by OpenCVE AI on July 17, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free Vulnerability in Chrome Android Omnibox Leads to Heap Corruption

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Android Omnibox Leading to Potential Heap Corruption

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Android Omnibox Leading to Potential Heap Corruption

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Android Omnibox Enables Potential Heap Corruption

Sun, 12 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Android Omnibox Enables Potential Heap Corruption

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Omnibox on Android Allows Heap Corruption via Crafted Page

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Omnibox on Android Allows Heap Corruption via Crafted Page

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Android Omnibox Allows Heap Corruption via Crafted Page

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Android Omnibox Allows Heap Corruption via Crafted Page

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Enables Remote Heap Corruption on Android

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Enables Remote Heap Corruption on Android

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Omnibox Use-After-Free Heap Corruption in Chrome on Android

Sun, 05 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Omnibox Use-After-Free Heap Corruption in Chrome on Android

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Omnibox Enables Heap Corruption

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Omnibox Enables Heap Corruption

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Omnibox Use-After-Free Heap Corruption in Chrome on Android

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Omnibox Use-After-Free Heap Corruption in Chrome on Android

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Allows Remote Code Execution via Crafted HTML

Thu, 02 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Allows Remote Code Execution via Crafted HTML

Thu, 02 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Android Omnibox Enables Heap Corruption for Remote Code Execution

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Android Omnibox Enables Heap Corruption for Remote Code Execution

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Enables Remote Heap Corruption via Crafted Web Pages

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Enables Remote Heap Corruption via Crafted Web Pages

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Allows Remote Heap Corruption via Crafted HTML Page

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Omnibox Allows Remote Heap Corruption via Crafted HTML Page

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:58:17.709Z

Reserved: 2026-06-29T23:04:16.062Z

Link: CVE-2026-14005

cve-icon Vulnrichment

Updated: 2026-07-01T14:43:31.844Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses