
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7345 is a sandbox escape vulnerability caused by insufficient validation of untrusted input in the Feedback component of Google Chrome. It affects all versions of Google Chrome prior to 147.0.7727.138 and was reported internally by Google on April 13, 2026, with public disclosure on April 28, 2026. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to potentially escape the Chrome sandbox. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, Chrome Release).
The vulnerability is classified as CWE-20 (Improper Input Validation), stemming from the Feedback component's failure to adequately validate untrusted input received from a compromised renderer process (GitHub Advisory). Exploitation requires the attacker to have already achieved renderer process compromise — a prerequisite that limits the attack surface but makes this a critical second-stage primitive in a full browser exploit chain. By delivering a crafted HTML page, the attacker can pass malicious input through the Feedback component in a way that bypasses sandbox restrictions, escalating from renderer-level access to broader system access. The Chromium issue tracker reference is bug 502248774, though details remain restricted pending widespread user updates (Chrome Release).
Successful exploitation allows an attacker who has compromised the Chrome renderer process to escape the browser sandbox, potentially gaining system-level access on the affected host. This represents a significant privilege escalation — from the restricted renderer context to the underlying operating system — enabling arbitrary code execution, access to sensitive data, and potential for lateral movement within a network. All three security dimensions (confidentiality, integrity, and availability) are rated High in the CVSS scoring, reflecting the severity of a full sandbox escape (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability was reported by Google's internal security team, suggesting it may have been discovered through internal auditing rather than external threat actor activity. The EPSS score is approximately 0.047% (0.000470), indicating a low near-term probability of exploitation. CVE-2026-7345 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a chained attack — first compromising the renderer process, then leveraging this flaw — which raises the practical bar for exploitation.
cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.chrome.exe or chrome spawning non-browser executables).Google has released a patch in Chrome version 147.0.7727.138 (Windows/Mac) and 147.0.7727.137 (Linux), which addresses this vulnerability along with 29 other security fixes (Chrome Release). Organizations should immediately update all Chrome installations to version 147.0.7727.138 or later. No configuration-based workaround is available; patching is the only remediation. Downstream distributions including Debian (Chromium) and openSUSE have also released updated packages incorporating this fix (Feedly). Enterprises should use fleet management tools (e.g., Google Admin Console, Qualys, Nessus) to verify patch deployment across all endpoints.
Google disclosed the vulnerability as part of a large Chrome stable channel update on April 28, 2026, covering 30 security fixes, with CVE-2026-7345 rated High severity (Chrome Release). Security aggregators including Kaspersky Threat Intelligence, VulDB, and BeyondMachines noted the update, highlighting the sandbox escape capability as a significant risk. Social media activity was limited, with automated CVE tracking accounts on Bluesky and Mastodon posting notifications. No major independent researcher commentary or detailed technical write-ups have been published as of the time of this report.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."