
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7334 is a use-after-free vulnerability in the Views component of Google Chrome on macOS, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.138 on Mac. The vulnerability was reported by security researcher Batuhan Eşref KOÇ on March 26, 2026, and publicly disclosed on April 28, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Google Chrome Advisory, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in the Views component of Google Chrome specifically on macOS. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires a victim to visit a specially crafted HTML page, after which the attacker can trigger the heap corruption condition in the Views rendering layer. The Chromium issue tracker references bug ID 496456528 for this vulnerability (Google Chrome Advisory, GitHub Advisory).
Successful exploitation could lead to heap corruption, potentially enabling remote code execution on affected macOS systems running a vulnerable version of Chrome. The vulnerability has high confidentiality, integrity, and availability impact, meaning an attacker could gain unauthorized access to sensitive data, modify system state, or crash the browser process. No privileges are required on the attacker's side, though user interaction (visiting a malicious page) is necessary (GitHub Advisory, Google Chrome Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.011% (0.025% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has addressed this vulnerability in Chrome stable channel version 147.0.7727.138 for Mac (and 147.0.7727.137 for Windows/Linux, released April 28, 2026). Users should update Google Chrome on macOS to version 147.0.7727.138 or later immediately. Enabling automatic updates in Chrome settings ensures timely receipt of future security patches. As a temporary measure prior to patching, restricting access to untrusted or unknown web content can reduce exposure (Google Chrome Advisory).
Google's April 28, 2026 stable channel update addressed 30 security fixes in total, with CVE-2026-7334 among the highlighted externally reported issues. The vulnerability was assigned a "High" severity rating by the Chromium security team and a bug bounty reward amount is listed as "TBD," indicating the reward had not yet been finalized at time of disclosure (Google Chrome Advisory). Downstream Linux distributions including Debian and openSUSE subsequently issued their own Chromium security advisories incorporating this fix.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."