Description
Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free in the password management component of Google Chrome that can be triggered by a crafted HTML page loaded in the browser. When activated it corrupts heap memory, which may lead to data corruption or potentially allow an attacker to gain further control. The vulnerability is classified as CWE‑416. The description does not claim that remote code execution is guaranteed, only that heap corruption is possible.

Affected Systems

All installations of Google Chrome earlier than version 150.0.7871.47 on any operating system are affected. The vendor, Google, listed the impact across all browsers, but the specific platforms are not enumerated. Therefore, any user running a vulnerable Chrome instance should consider itself at risk until the approved update is installed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity impact, yet the EPSS score of less than 1% reflects a current low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves delivering a malicious HTML page to a victim’s browser, which would trigger the heap corruption when the Passwords component processes the page. No immediate exploit code has been disclosed, so the threat currently remains theoretical but should be treated seriously.

Generated by OpenCVE AI on July 21, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Google Chrome update to 150.0.7871.47 or later.
  • Enable automatic browser updates to ensure timely receipt of security patches.
  • Monitor threat intelligence feeds for new exploit discovery related to this use‑after‑free vulnerability.

Generated by OpenCVE AI on July 21, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Password Management Allows Heap Corruption via Crafted HTML

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Passwords Enables Heap Corruption

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Passwords Enables Heap Corruption

Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Passwords Enables Heap Corruption via Crafted HTML Page

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Passwords Enables Heap Corruption via Crafted HTML Page

Sun, 12 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Component Enables Remote Heap Corruption

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Component Enables Remote Heap Corruption

Fri, 10 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Heap Corruption via Crafted HTML Page

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Heap Corruption via Crafted HTML Page

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Potential Heap Corruption via Crafted HTML

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Potential Heap Corruption via Crafted HTML

Tue, 07 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Leads to Potential Heap Corruption

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Leads to Potential Heap Corruption

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Causing Potential Heap Corruption

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Causing Potential Heap Corruption

Sat, 04 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords May Cause Heap Corruption

Sat, 04 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords May Cause Heap Corruption

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Leading to Heap Corruption

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Leading to Heap Corruption

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Use-After-Free in Chrome Passwords

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Use-After-Free in Chrome Passwords

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Heap Corruption via Crafted HTML

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Passwords Enables Heap Corruption via Crafted HTML

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Chrome Password Manager Use‑ to Heap Corruption

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Chrome Password Manager Use‑After‑Free Leading to Heap Corruption Chrome Password Manager Use‑ to Heap Corruption

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Password Manager Use‑After‑Free Leading to Heap Corruption

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:38:42.829Z

Reserved: 2026-06-29T23:11:42.576Z

Link: CVE-2026-14102

cve-icon Vulnrichment

Updated: 2026-07-01T15:38:29.228Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:45:08Z

Weaknesses