CVE-2014-1732
published 2014-04-26CVE-2014-1732: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.62%
73.8th percentile
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble window for an incorrect duration.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 34.0.1847.131 | 34.0.1847.131 | |
| chrome | < 34.0.1847.132 | 34.0.1847.132 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome 34.0.1847.130/34.0.1847.131 Speech Recognition resource management (Nessus ID 73856 / ID 166990)
vuldb·2026-05-12·CVSS 7.5
CVE-2014-1732 [HIGH] Google Chrome 34.0.1847.130/34.0.1847.131 Speech Recognition resource management (Nessus ID 73856 / ID 166990)
A vulnerability was found in Google Chrome 34.0.1847.130/34.0.1847.131 and classified as critical. Affected by this issue is some unknown functionality of the component Speech Recognition. The manipulation results in improper resource management.
This vulnerability is known as CVE-2014-1732. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-q77g-pr8j-57vw: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views
ghsa_unreviewed·2022-05-17
CVE-2014-1732 [HIGH] CWE-416 GHSA-q77g-pr8j-57vw: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble window for an incorrect duration.
OSV
CVE-2014-1732: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views
osv·2014-04-26·CVSS 7.5
CVE-2014-1732 [HIGH] CVE-2014-1732: Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble window for an incorrect duration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=352851https://src.chromium.org/viewvc/chrome?revision=261737&view=revisionhttp://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=352851https://src.chromium.org/viewvc/chrome?revision=261737&view=revision
2014-04-26
Published