CVE-2026-7349
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-7349 is a use-after-free vulnerability in the Cast functionality of Google Chrome, allowing an attacker on the local network segment to execute arbitrary code inside the browser's sandbox via malicious network traffic. It affects all Google Chrome versions prior to 147.0.7727.138. The vulnerability was reported internally by Google on April 6, 2026, and publicly disclosed on April 28, 2026, alongside a stable channel update. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Chrome Releases).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Cast component — the feature responsible for streaming content to Chromecast and compatible devices. A use-after-free condition arises when memory associated with a Cast-related object is freed but subsequently referenced, allowing an attacker to potentially control the freed memory region and redirect code execution. Exploitation requires the attacker to be on the same local network segment as the victim and to craft specific malicious network traffic targeting the Cast subsystem; no user interaction or authentication is required, though attack complexity is rated High. The Chromium issue tracker entry is tracked under issue ID 500034684 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows an attacker on the local network to execute arbitrary code within Chrome's sandbox environment, impacting confidentiality, integrity, and availability at a high level. While sandbox containment limits the immediate blast radius, a sandbox escape chained with this vulnerability could lead to full browser process compromise and access to sensitive user data. The attack is constrained to the local network segment, reducing the scope of exposure compared to remotely exploitable vulnerabilities (GitHub Advisory, Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.011% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, rolling out as of April 28, 2026. Users and administrators should immediately update all Chrome installations to version 147.0.7727.138 or later. As an interim measure, organizations that do not require Cast functionality can consider disabling it via enterprise policy or restricting local network access to reduce exposure (Chrome Releases, GitHub Advisory).

Community reactions

The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security news aggregators and vulnerability tracking services including Kaspersky Threat Intelligence, Tenable/Nessus, Qualys, and Linux distribution security advisories for Debian, Fedora, and openSUSE (Chrome Releases). No notable individual researcher commentary or significant social media discussion specific to CVE-2026-7349 has been identified beyond routine CVE tracking posts.

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19143HIGH8.6
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui
NoYesAug 06, 2026
CVE-2026-19154HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-qt6-ui
NoYesAug 06, 2026
CVE-2026-19141HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui
NoYesAug 06, 2026
CVE-2026-15769HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-debuginfo
NoYesJul 14, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management