
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7355 is a use-after-free vulnerability in the Media component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.138. The vulnerability was reported internally by Google on 2026-03-31 and publicly disclosed on April 28, 2026, as part of a 30-fix stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Chrome Release).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Media component when memory that has been freed is subsequently referenced or reused, creating a condition where an attacker can manipulate the freed memory region. An attacker exploits this by serving a specially crafted HTML page that triggers the improper memory handling in the media processing subsystem; user interaction (visiting the malicious page) is required. The bug was tracked internally as Chromium issue 498285711 and was detected using Google's memory safety tooling (AddressSanitizer, MemorySanitizer, libFuzzer, or AFL). Despite the CVSS score of 8.8, Chromium's internal severity assessment rated this as Medium, reflecting the sandbox containment that limits the immediate blast radius (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, impacting confidentiality, integrity, and availability of the browser process. While sandbox containment limits direct access to the underlying operating system, code execution within the sandbox can serve as a stepping stone for a sandbox escape if chained with a second vulnerability. Sensitive data processed by the browser (credentials, session tokens, page content) could be exposed, and the browser process itself could be crashed or hijacked (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.038–0.045%, placing it in the 14th percentile for exploitation likelihood within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by Google's own security team, suggesting it was found through internal fuzzing rather than external adversarial research.
Google has released a patch in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, which addresses this vulnerability along with 29 other security fixes (Chrome Release). Organizations should immediately update all Chrome installations to version 147.0.7727.138 or later and enforce browser update policies enterprise-wide. As a temporary control while patches are being deployed, restricting access to untrusted or unknown websites can reduce exposure. Chrome's sandbox provides some inherent protection, but patching should not be delayed.
Google's April 28, 2026 stable channel blog post disclosed the fix as part of a large 30-vulnerability update, with CVE-2026-7355 rated Medium severity by the Chromium security team despite its CVSS 8.8 score (Chrome Release). Security aggregators including Kaspersky Threat Intelligence, Tenable (Nessus plugins 311477, 311819, 312117, 312245), Qualys, and openSUSE security lists published detection and advisory content shortly after disclosure. Community coverage on Bluesky and Mastodon noted the update, and threat digest services such as Hawk-Eye included it in their weekly roundups, though no significant controversy or researcher commentary specific to this CVE has emerged.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."