CVE-2026-14048
published 2026-06-30CVE-2026-14048: Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive…
PriorityP428medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.12%
1.9th percentile
Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.46 | 150.0.7871.46 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious pe
ghsa_unreviewed·2026-07-01
CVE-2026-14048 [MEDIUM] CWE-416 Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious pe
Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)
Chrome
Stable Channel Update for Desktop: CVE-2026-14046
vendor_chrome·2026-06-30
CVE-2026-14046 [LOW] Stable Channel Update for Desktop: CVE-2026-14046
Stable Channel Update for Desktop
CVE-2026-14046: Inappropriate implementation in CustomTabs. Reported by Google on 2026-03-30 [N/A][ 498864176 ] Low CVE-2026-14047: Insufficient policy enforcement in Extensions
Reported by Google on 2026-04-02 [N/A][ 499189601 ] Low CVE-2026-14048: Use after free in Chromecast
Severity: low
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published