
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7342 is a use-after-free vulnerability in the WebView component of Google Chrome on Android, allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It was reported internally by Google on April 17, 2026, and disclosed publicly on April 28, 2026, as part of a stable channel update. The vulnerability affects all Google Chrome versions prior to 147.0.7727.138 on Android. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in the WebView component of Chrome on Android. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires a victim to visit or be redirected to a specially crafted HTML page, after which the attacker can achieve arbitrary code execution within the Chrome sandbox. The bug was tracked internally as Chromium issue 503889643 and was identified by Google's own security team (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox on Android devices, with high impacts to confidentiality, integrity, and availability. While execution is confined to the sandbox, this could expose sensitive browser data such as cookies, credentials, and browsing history, and may serve as a stepping stone toward a full sandbox escape if chained with additional vulnerabilities. The scope of impact is limited to the Chrome process on Android, but the breadth of Chrome's Android user base makes this a significant risk (GitHub Advisory, Chrome Releases).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability was discovered and reported by Google's internal security team, suggesting it was identified proactively rather than through observed attacks. The EPSS score is approximately 0.033–0.049%, placing it in the lower percentiles for near-term exploitation likelihood. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Google has released a fix in Chrome version 147.0.7727.138 for Android (and 147.0.7727.137/138 for Windows/Mac/Linux). Users should update Chrome on Android to version 147.0.7727.138 or later immediately. Enabling automatic Chrome updates on Android devices is strongly recommended to ensure timely patching. As a temporary measure, restricting access to untrusted or unknown websites and implementing content filtering policies can reduce exposure until the patch is deployed (Chrome Releases, GitHub Advisory).
The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security news aggregators and Linux distribution security lists (Debian, openSUSE, Fedora) as they packaged updated Chromium builds. Kaspersky's threat intelligence portal and Tenable's Nessus scanner also published detection content shortly after disclosure. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-7342 has been identified beyond routine vulnerability tracking (Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."