Description
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw (CWE‑416) in the Chrome user interface allows a crafted web page to trigger heap corruption when a user performs certain UI gestures. This corruption can cause the browser to crash, result in a denial of service, or potentially enable an attacker to execute arbitrary code. The advisory does not confirm that remote code execution is guaranteed, but the presence of heap corruption means that integrity and confidentiality of user data could be at risk if exploitation succeeds.

Affected Systems

Desktop versions of Google Chrome prior to 150.0.7871.182 are affected. The CVE does not specify operating systems, so the platforms impacted are inferred to be the typical supported platforms for Chrome (Windows, macOS, Linux).

Risk and Exploitability

The CVSS score of 8.8 places this issue in the high severity range. An EPSS score of < 1% indicates that current exploitation attempts are unlikely but still possible, especially in targeted or persistent campaigns. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering: an attacker must persuade a user to visit a malicious web page and then perform the specific UI gestures, pointing to a drive‑by or phishing‑like vector.

Generated by OpenCVE AI on August 4, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.182 or later to receive the vendor patch
  • Avoid interacting with unknown or suspicious web pages that may contain malicious content
  • Configure Chrome update settings to enforce automatic upgrades on all supported platforms

Generated by OpenCVE AI on August 4, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Exploit in Chrome User Interface Leading to Heap Corruption

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Exploit in Chrome User Interface Leading to Heap Corruption

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome UI Leading to Heap Corruption

Sun, 26 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome UI Leading to Heap Corruption

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-22T13:43:16.032Z

Reserved: 2026-07-20T22:23:07.179Z

Link: CVE-2026-16423

cve-icon Vulnrichment

Updated: 2026-07-22T13:43:00.840Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses