Description
Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the audio component of Google Chrome on Linux can be triggered by a crafted web page. The flaw, classified as CWE‑416, allows a remote attacker to execute arbitrary code on the host machine, but the specific user action is inferred to be visiting a malicious page. This results in full compromise of the affected system.

Affected Systems

Google Chrome for Linux is impacted for all releases prior to version 150.0.7871.47. Any instance of Chrome in that version range is vulnerable, regardless of the operating system distribution, until the patch is applied.

Risk and Exploitability

The CVSS score of 8.8 marks the vulnerability as high severity, while the EPSS score of <1% indicates current exploitation attempts are unlikely. The flaw is not listed in CISA’s KEV catalog. Attackers can deliver a specially crafted HTML page to a vulnerable user, and upon rendering the audio subsystem’s use‑after‑free enables arbitrary code execution with the privileges of the Chrome user. This method is inferred from the description.

Generated by OpenCVE AI on July 21, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Linux to version 150.0.7871.47 or newer, which contains the audio module patch.
  • If an upgrade cannot be performed immediately, launch Chrome with the flag "--disable-audio" to turn off the vulnerable audio subsystem until the update is applied.
  • Ensure the system is enrolled in Chrome’s automatic update service and monitor for trusted or suspicious web content while the vulnerability remains unpatched.

Generated by OpenCVE AI on July 21, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Free in Chrome Audio on Linux

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Audio Enables Remote Code Execution on Linux

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Audio Enables Remote Code Execution on Linux

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution from Crafted HTML Page

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution from Crafted HTML Page

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution on Linux

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution on Linux

Thu, 09 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Chromium Audio Use‑After‑Free Enables Remote Code Execution on Linux

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chromium Audio Use‑After‑Free Enables Remote Code Execution on Linux

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio Enables Remote Code Execution on Linux

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio Enables Remote Code Execution on Linux

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free Vulnerability in Chrome Audio on Linux Allows Remote Code Execution

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free Vulnerability in Chrome Audio on Linux Allows Remote Code Execution

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio on Linux Enables Remote Code Execution

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio on Linux Enables Remote Code Execution

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Audio Module Use‑After‑Free in Chrome for Linux

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Audio Module Use‑After‑Free in Chrome for Linux

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio Module Enables Remote Code Execution on Linux

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Audio Module Enables Remote Code Execution on Linux

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Audio Allows Remote Code Execution

Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use-after-Free in Chrome Audio Component Enables Remote Code Execution via Malicious Webpage

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Use-after-Free in Chrome Audio Component Enables Remote Code Execution via Malicious Webpage

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:11.980Z

Reserved: 2026-06-29T23:11:51.669Z

Link: CVE-2026-14149

cve-icon Vulnrichment

Updated: 2026-07-01T13:58:33.323Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:30:07Z

Weaknesses