
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14107 is a use-after-free vulnerability in the Scheduling component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 150.0.7871.47 on Windows/Mac and 150.0.7871.46 on Linux. The vulnerability was disclosed on June 30, 2026, and a patch was released the same day as part of the Chrome 150 stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) and is rated "Low" severity by Chromium's internal security severity scale (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Scheduling component — the subsystem responsible for managing task execution and timing within the browser. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the erroneous memory access within the sandboxed renderer process. The Chromium issue tracker reference is bug ID 513544566, though full technical details remain restricted pending broad user adoption of the patch (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code within the Chrome renderer sandbox by convincing a user to visit a malicious webpage. The CVSS assessment reflects high confidentiality, integrity, and availability impact, meaning an attacker could potentially read sensitive browser data, corrupt memory, or crash the browser process. Because exploitation is confined to the sandbox, a full system compromise would require chaining this vulnerability with a sandbox escape; however, in-sandbox code execution can still expose session data, credentials stored in the browser, and browsing history (GitHub Advisory).
Google has released a patch in Chrome 150.0.7871.47 (Windows/Mac) and 150.0.7871.46 (Linux) as part of the Chrome 150 stable channel update. Users and administrators should update Google Chrome to version 150.0.7871.47 or later immediately. Enterprise administrators should enforce automatic Chrome updates via policy and educate users to avoid visiting untrusted or suspicious websites. No configuration-based workaround is available; updating to the patched version is the only remediation (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."