
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7347 is a use-after-free vulnerability in the Chromoting component of Google Chrome that allows a remote attacker to execute arbitrary code via malicious network traffic. It affects all Google Chrome versions prior to 147.0.7727.138. The vulnerability was reported internally by Google on April 11, 2026, and patched in the stable channel update released April 28, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Chrome Releases).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Chromoting component — the remote desktop protocol implementation used by Chrome Remote Desktop. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the freed memory region and redirect execution flow. Because the attack vector is network-based and requires no user interaction, exploitation can be triggered entirely through crafted malicious network traffic directed at the Chromoting service. The bug was tracked internally as Chromium issue 501722605 and was discovered and reported by Google's own security team (Chrome Releases, GitHub Advisory).
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system with the privileges of the Chrome process, resulting in high confidentiality, integrity, and availability impact. An attacker could access sensitive user data, modify system state, or cause a denial of service. Because no user interaction is required, the attack surface extends to any system running a vulnerable Chrome version with Chromoting (Chrome Remote Desktop) active and reachable over the network (GitHub Advisory, Chrome Releases).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.087%, indicating a low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack complexity is rated High, meaning exploitation requires specific conditions to be met, which somewhat limits opportunistic exploitation.
Google has released a fix in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, published April 28, 2026. All users and organizations should update Google Chrome to version 147.0.7727.138 or later immediately. As an interim measure, organizations should consider disabling or restricting access to Chrome Remote Desktop (Chromoting) on systems where it is not required, and monitor for unusual network traffic targeting the Chromoting service (Chrome Releases, GitHub Advisory).
The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security news aggregators and vulnerability tracking services including Kaspersky Threat Intelligence, Tenable/Nessus, Qualys, and Linux distribution security lists (Debian, openSUSE, Fedora). Social media mentions were noted on Mastodon via The Hacker Wire. No notable individual researcher commentary or significant controversy has been identified beyond standard patch notification coverage (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."