CVE-2014-7907: Google Chrome

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the (1) lock and (2) unlock methods.

Affected products

  • Google Chrome: up to and including 39.0.2171.45

Published 2014-11-19. Last modified 2026-06-17.