Description
Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-07-01
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the Dawn rendering engine in Google Chrome. A crafted HTML page can cause the browser to free an object while it is still referenced, allowing an attacker to escape the renderer sandbox and potentially execute code outside the browser. This flaw is rated as CWE‑416, indicating a memory safety issue that can lead to arbitrary code execution.

Affected Systems

The issue affects desktop versions of Google Chrome on the stable channel that are older than 150.0.7871.46. Based on the description, it is inferred that users on Windows, macOS, or Linux who have not upgraded to this or newer releases are at risk. The rendering engine behavior is identical across platforms, so the impact is uniform regardless of OS.

Risk and Exploitability

The CVSS score of 9.6 reflects a high severity remote exploit potential. The EPSS score is below 1%, suggesting that the likelihood of exploitation remains low at the time of analysis, though the existence of a critical flaw in a widely used browser warrants attention. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the most probable attack vector is a maliciously crafted HTML page that the user opens, which could be delivered remotely or via local phishing. The exploitation would provide an attacker with sandbox escape, potentially leading to full system compromise.

Generated by OpenCVE AI on July 21, 2026 at 12:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to 150.0.7871.46 or a newer release.
  • Verify that Chrome’s sandbox remains enabled and is not overridden by extensions or group policy.
  • Disable or remove any extensions that grant elevated privileges to the renderer or otherwise bypass the sandbox.

Generated by OpenCVE AI on July 21, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Dawn Rendering Engine Leading to Sandbox Escape

Fri, 17 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Enables Sandbox Escape

Tue, 14 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Enables Sandbox Escape

Mon, 13 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use-After‑Free Vulnerability in Chrome’s Dawn Engine Enables Sandbox Escape

Sun, 12 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use-After‑Free Vulnerability in Chrome’s Dawn Engine Enables Sandbox Escape

Sat, 11 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Dawn Rendering Engine Enables Sandbox Escapes

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Dawn Rendering Engine Enables Sandbox Escapes

Thu, 09 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Dawn Enables Sandbox Escape via Crafted Web Page

Wed, 08 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Dawn Enables Sandbox Escape via Crafted Web Page

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Enables Sandbox Escape

Tue, 07 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Enables Sandbox Escape

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Engine Allows Sandbox Escape

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Engine Allows Sandbox Escape

Sun, 05 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Allowing Sandbox Escape

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Dawn Rendering Engine Allowing Sandbox Escape

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Dawn Rendering Engine Enables Potential Sandbox Escape

Fri, 03 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Dawn Rendering Engine Enables Potential Sandbox Escape

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's Dawn Engine Enables Sandbox Escape

Thu, 02 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's Dawn Engine Enables Sandbox Escape

Thu, 02 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Dawn Enabling Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Dawn Enabling Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:21.979Z

Reserved: 2026-07-01T21:37:32.392Z

Link: CVE-2026-14417

cve-icon Vulnrichment

Updated: 2026-07-02T00:01:02.445Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:00:04Z

Weaknesses