
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7356 is a use-after-free vulnerability in the Navigation component of Google Chrome that allows a remote attacker to execute arbitrary code via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.138 on Windows/Mac and 147.0.7727.137 on Linux. The vulnerability was reported internally by Google on March 30, 2026, and publicly disclosed on April 28, 2026, alongside a stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Navigation component. A use-after-free condition arises when memory associated with a navigation-related object is freed but subsequently referenced, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the memory corruption in the browser process. The Chromium issue tracker entry (ID 497769116) is currently restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the Chrome renderer or browser process, potentially leading to full compromise of the affected system. This could result in theft of sensitive data (credentials, cookies, browsing history), installation of malware, or use of the compromised host as a pivot point for lateral movement within a network. All three security dimensions — confidentiality, integrity, and availability — are rated High (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability was reported by Google's internal security team, and bug details remain restricted in the Chromium issue tracker. The EPSS score is approximately 0.038–0.045%, placing it in the lower percentiles for near-term exploitation likelihood. No threat actor attribution has been made, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog.
cmd.exe, powershell.exe, bash, curl, wget) not associated with normal browser activity; Chrome renderer processes exhibiting unusual CPU or memory spikes.Google has released a patch in Chrome stable channel version 147.0.7727.138 for Windows and Mac, and 147.0.7727.137 for Linux. Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Enterprise administrators should enforce automatic Chrome updates via Group Policy (Windows) or mobile device management solutions. As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites and consider using browser isolation technologies (Chrome Releases, GitHub Advisory).
The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security aggregators and Linux distribution maintainers including Debian, Fedora, and openSUSE, who issued downstream Chromium advisories. Kaspersky's threat intelligence portal and Beyond Machines noted the breadth of the April 28, 2026 Chrome update. No significant independent researcher commentary or social media controversy specific to CVE-2026-7356 has been identified, consistent with the absence of a public exploit or active exploitation (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."