
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7349 is a use-after-free vulnerability in the Cast functionality of Google Chrome, allowing an attacker on the local network segment to execute arbitrary code inside the browser's sandbox via malicious network traffic. It affects all Google Chrome versions prior to 147.0.7727.138. The vulnerability was reported internally by Google on April 6, 2026, and publicly disclosed on April 28, 2026, alongside a stable channel update. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Chrome Releases).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Cast component — the feature responsible for streaming content to Chromecast and compatible devices. A use-after-free condition arises when memory associated with a Cast-related object is freed but subsequently referenced, allowing an attacker to potentially control the freed memory region and redirect code execution. Exploitation requires the attacker to be on the same local network segment as the victim and to craft specific malicious network traffic targeting the Cast subsystem; no user interaction or authentication is required, though attack complexity is rated High. The Chromium issue tracker entry is tracked under issue ID 500034684 (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker on the local network to execute arbitrary code within Chrome's sandbox environment, impacting confidentiality, integrity, and availability at a high level. While sandbox containment limits the immediate blast radius, a sandbox escape chained with this vulnerability could lead to full browser process compromise and access to sensitive user data. The attack is constrained to the local network segment, reducing the scope of exposure compared to remotely exploitable vulnerabilities (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.011% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released a patch in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, rolling out as of April 28, 2026. Users and administrators should immediately update all Chrome installations to version 147.0.7727.138 or later. As an interim measure, organizations that do not require Cast functionality can consider disabling it via enterprise policy or restricting local network access to reduce exposure (Chrome Releases, GitHub Advisory).
The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security news aggregators and vulnerability tracking services including Kaspersky Threat Intelligence, Tenable/Nessus, Qualys, and Linux distribution security advisories for Debian, Fedora, and openSUSE (Chrome Releases). No notable individual researcher commentary or significant social media discussion specific to CVE-2026-7349 has been identified beyond routine CVE tracking posts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."