Description
Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw located in the Views component of Google Chrome on macOS. It requires a remote attacker to deliver a crafted HTML page that causes the browser to execute a prescribed sequence of user‑initiated UI gestures, which can trigger heap corruption.

Affected Systems

Google Chrome on macOS versions earlier than 150.0.7871.47 are affected. The update 150.0.7871.47 in the stable channel includes the fix.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity, indicating substantial potential impact if exploited. The EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. It is inferred that exploitation requires a remote attacker to supply the malicious web page and persuade a user to perform the specific gestures; after the gestures, heap corruption could be leveraged by an attacker with further privileges.

Generated by OpenCVE AI on August 4, 2026 at 08:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to apply the fix for the use‑after‑free flaw in Views.
  • If an immediate update is not feasible, restrict access to untrusted web content that could trigger the flaw, for example by applying network filtering or browser security policies.
  • Ensure Chrome runs in its default sandbox and consider additional isolation such as site isolation to contain any damage from a heap corruption.

Generated by OpenCVE AI on August 4, 2026 at 08:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Mac Chrome Views Enables Heap Corruption via Crafted HTML Page

Wed, 29 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Mac Chrome Views Enables Heap Corruption via Crafted HTML Page

Sat, 25 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Use macOS Allows Remote Exploit

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Use macOS Allows Remote Exploit

Thu, 16 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component on macOS

Tue, 14 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component on macOS

Mon, 13 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Views on macOS Enables Heap Corruption via Crafted Web Page

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Views on macOS Enables Heap Corruption via Crafted Web Page

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Use-after-Free Heap Corruption in Chrome Views on macOS

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Use-after-Free Heap Corruption in Chrome Views on macOS

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views on macOS Allows Heap Corruption via Crafted Web Page

Tue, 07 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views on macOS Allows Heap Corruption via Crafted Web Page

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Component Allows Heap Corruption via Crafted HTML on macOS

Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Component Allows Heap Corruption via Crafted HTML on macOS

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component Exploitable via Crafted Web Page

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Component Exploitable via Crafted Web Page

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Mac Views Allows Heap Corruption via Crafted Web Page

Sat, 04 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Mac Views Allows Heap Corruption via Crafted Web Page

Fri, 03 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Component on macOS Leads to Heap Corruption

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Component on macOS Leads to Heap Corruption

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption via UI Gestures in Google Chrome on macOS

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Heap Corruption via UI Gestures in Google Chrome on macOS

Thu, 02 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Chrome macOS Views Component Use‑After‑Free Leading to Heap Corruption

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Chrome macOS Views Component Use‑After‑Free Leading to Heap Corruption

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Heap Corruption on macOS

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Views Enables Heap Corruption on macOS

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:57:49.378Z

Reserved: 2026-06-29T23:04:21.134Z

Link: CVE-2026-14025

cve-icon Vulnrichment

Updated: 2026-07-01T13:45:58.027Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses