Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-14121: Google Chrome on Linux: Malicious Network Traffic Can Execute Code

CVE-2026-14121 · published 3 months ago
Summary

A vulnerability in Google Chrome on Linux allowed a remote attacker to potentially execute arbitrary code on a user's system. This means a hacker could send malicious traffic to a user's browser and potentially take control of their system. To stay safe, make sure your Google Chrome browser is up to date, especially if you're using Linux.

What to do
  • Update google chrome to version 150.0.7871.47 or later.
Affected software
Ecosystem VendorProductAffected versions
– google chrome < 150.0.7871.47
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Debian:11 debian chromium All versions
Debian:12 debian chromium All versions
Debian:13 debian chromium All versions
Debian:14 debian chromium All versions
Original advisory text
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published30 Jun 2026
Updated1 Oct 2026
First seen1 Jul 2026
Sources
Track software like this
Free during beta