Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-7345
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-7345 is a sandbox escape vulnerability caused by insufficient validation of untrusted input in the Feedback component of Google Chrome. It affects all versions of Google Chrome prior to 147.0.7727.138 and was reported internally by Google on April 13, 2026, with public disclosure on April 28, 2026. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to potentially escape the Chrome sandbox. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, Chrome Release).

Technical details

The vulnerability is classified as CWE-20 (Improper Input Validation), stemming from the Feedback component's failure to adequately validate untrusted input received from a compromised renderer process (GitHub Advisory). Exploitation requires the attacker to have already achieved renderer process compromise — a prerequisite that limits the attack surface but makes this a critical second-stage primitive in a full browser exploit chain. By delivering a crafted HTML page, the attacker can pass malicious input through the Feedback component in a way that bypasses sandbox restrictions, escalating from renderer-level access to broader system access. The Chromium issue tracker reference is bug 502248774, though details remain restricted pending widespread user updates (Chrome Release).

Impact

Successful exploitation allows an attacker who has compromised the Chrome renderer process to escape the browser sandbox, potentially gaining system-level access on the affected host. This represents a significant privilege escalation — from the restricted renderer context to the underlying operating system — enabling arbitrary code execution, access to sensitive data, and potential for lateral movement within a network. All three security dimensions (confidentiality, integrity, and availability) are rated High in the CVSS scoring, reflecting the severity of a full sandbox escape (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability was reported by Google's internal security team, suggesting it may have been discovered through internal auditing rather than external threat actor activity. The EPSS score is approximately 0.047% (0.000470), indicating a low near-term probability of exploitation. CVE-2026-7345 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a chained attack — first compromising the renderer process, then leveraging this flaw — which raises the practical bar for exploitation.

Exploitation steps

  1. Renderer Compromise: The attacker must first exploit a separate renderer-level vulnerability (e.g., a V8 type confusion or use-after-free bug) to gain code execution within the Chrome renderer process sandbox.
  2. Craft Malicious HTML Page: Prepare a specially crafted HTML page that triggers the Feedback component's input handling in a way that passes malicious, insufficiently validated data across the sandbox boundary.
  3. Deliver to Target: Lure the victim to visit the malicious page via phishing, malvertising, or a compromised website, causing Chrome to load and process the crafted content.
  4. Trigger Sandbox Escape: The crafted input exploits the validation flaw in the Feedback component, allowing the renderer process to interact with privileged browser or OS resources outside the sandbox.
  5. Achieve System Access: With the sandbox escaped, the attacker can execute arbitrary code at the browser process privilege level or higher, enabling persistence, data theft, or lateral movement (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Process: Unusual child processes spawned by the Chrome renderer process (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.
  • Network: Unexpected outbound connections from the Chrome browser process to unknown or suspicious IP addresses, particularly following user visits to unfamiliar websites.
  • Logs: Browser crash reports or unexpected termination of Chrome sandbox processes; system event logs showing process creation from Chrome's renderer (chrome.exe or chrome spawning non-browser executables).
  • File System: New or modified files in user-writable directories created by Chrome processes; unexpected executables or scripts dropped in temp directories shortly after browser activity.

Mitigation and workarounds

Google has released a patch in Chrome version 147.0.7727.138 (Windows/Mac) and 147.0.7727.137 (Linux), which addresses this vulnerability along with 29 other security fixes (Chrome Release). Organizations should immediately update all Chrome installations to version 147.0.7727.138 or later. No configuration-based workaround is available; patching is the only remediation. Downstream distributions including Debian (Chromium) and openSUSE have also released updated packages incorporating this fix (Feedly). Enterprises should use fleet management tools (e.g., Google Admin Console, Qualys, Nessus) to verify patch deployment across all endpoints.

Community reactions

Google disclosed the vulnerability as part of a large Chrome stable channel update on April 28, 2026, covering 30 security fixes, with CVE-2026-7345 rated High severity (Chrome Release). Security aggregators including Kaspersky Threat Intelligence, VulDB, and BeyondMachines noted the update, highlighting the sandbox escape capability as a significant risk. Social media activity was limited, with automated CVE tracking accounts on Bluesky and Mastodon posting notifications. No major independent researcher commentary or detailed technical write-ups have been published as of the time of this report.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 147.0.7727.137-1~deb12u1

Fixed

sid

chromium: 147.0.7727.137-1

Fixed

trixie

chromium: 147.0.7727.137-1~deb13u1

Fixed

Alpine

Fixed

edge

qt6-qtwebengine: 6.11.0-r7

Fixed

v3.23

qt6-qtwebengine: 6.10.3-r1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management