Description
Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use–after–free condition in the navigation component of Google Chrome. A malformed HTML document can cause the browser to dereference memory that has already been freed, enabling an attacker who can serve a crafted page to execute arbitrary code with the privileges of the user’s Chrome process. The weakness is classified as CWE‑416 and allows complete compromise of the victim system.

Affected Systems

All installations of Google Chrome older than version 150.0.7871.47 are affected. The CVE data does not explicitly state which operating systems are impacted to Chrome across all platforms where the navigation component is present.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of current exploitation. The CVSS score of 8.8 denotes high severity. The vulnerability is not listed in CISA KEV. The likely attack vector is a malicious or compromised web page served by an attacker; delivery of a crafted HTML document can trigger the attacker to execute arbitrary code within the Chrome process with the same privileges as the logged‑in user.

Generated by OpenCVE AI on July 17, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later as soon as the update is available.
  • Configure Chrome’s Safe Browsing and URL blocklist features to mitigate use‑after‑free risks (CWE‑416) and prevent users from visiting suspicious sites.
  • In environments where an immediate update is not possible, apply enterprise policy controls to restrict or block untrusted web content and limit access to the affected navigation features until the patch is applied.

Generated by OpenCVE AI on July 17, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Enables Remote Code Execution via Crafted HTML

Thu, 16 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Allows Remote Code Execution

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Allows Remote Code Execution

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Navigation Enables Remote Code Execution via Crafted Web Page

Sun, 12 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Navigation Enables Remote Code Execution via Crafted Web Page

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Navigation Leading to Remote Code Execution

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Navigation Leading to Remote Code Execution

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Enables Remote Code Execution

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Enables Remote Code Execution

Wed, 08 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Enables Remote Code Execution

Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Enables Remote Code Execution

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Navigation Enables Remote Code Execution

Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Navigation Enables Remote Code Execution

Sun, 05 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Allows Remote Code Execution

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Allows Remote Code Execution

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Allows Remote Code Execution

Fri, 03 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Allows Remote Code Execution

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Component Enables Remote Code Execution

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Component Enables Remote Code Execution

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Enables Remote Code Execution via Crafted HTML

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Navigation Enables Remote Code Execution via Crafted HTML

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Leading to Remote Code Execution

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Leading to Remote Code Execution

Wed, 01 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Component Enables Remote Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Component Enables Remote Code Execution

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Enables Remote Code Execution

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Navigation Enables Remote Code Execution

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:49.850Z

Reserved: 2026-06-29T23:04:16.310Z

Link: CVE-2026-14006

cve-icon Vulnrichment

Updated: 2026-07-01T14:02:44.246Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses