CVE-2026-7356
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-7356 is a use-after-free vulnerability in the Navigation component of Google Chrome that allows a remote attacker to execute arbitrary code via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.138 on Windows/Mac and 147.0.7727.137 on Linux. The vulnerability was reported internally by Google on March 30, 2026, and publicly disclosed on April 28, 2026, alongside a stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Navigation component. A use-after-free condition arises when memory associated with a navigation-related object is freed but subsequently referenced, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the memory corruption in the browser process. The Chromium issue tracker entry (ID 497769116) is currently restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the Chrome renderer or browser process, potentially leading to full compromise of the affected system. This could result in theft of sensitive data (credentials, cookies, browsing history), installation of malware, or use of the compromised host as a pivot point for lateral movement within a network. All three security dimensions — confidentiality, integrity, and availability — are rated High (GitHub Advisory, Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability was reported by Google's internal security team, and bug details remain restricted in the Chromium issue tracker. The EPSS score is approximately 0.038–0.045%, placing it in the lower percentiles for near-term exploitation likelihood. No threat actor attribution has been made, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.138 (Windows/Mac) or 147.0.7727.137 (Linux), using browser fingerprinting techniques or social engineering to confirm the target's browser version.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers the use-after-free condition in Chrome's Navigation component — likely by manipulating navigation events (e.g., rapid page transitions, history manipulation, or iframe navigation) to cause a navigation object to be freed while still referenced.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing email, malicious advertisement, or compromised website.
  4. Trigger memory corruption: When the victim loads the page in a vulnerable Chrome version, the crafted navigation sequence triggers the use-after-free, corrupting heap memory in the browser process.
  5. Achieve code execution: By controlling the freed memory region (e.g., through heap grooming techniques), the attacker redirects execution to a shellcode or ROP chain, achieving arbitrary code execution with Chrome process privileges (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome process to unknown external IP addresses or domains shortly after visiting an unfamiliar website; unusual DNS queries originating from the browser process.
  • Process: Anomalous child processes spawned by Chrome (e.g., cmd.exe, powershell.exe, bash, curl, wget) not associated with normal browser activity; Chrome renderer processes exhibiting unusual CPU or memory spikes.
  • Logs: Browser crash reports or minidumps referencing the Navigation component; Windows Event Logs or Linux syslog entries showing unexpected process creation by the Chrome binary.
  • File System: Unexpected files written to the user's temp directory or Chrome profile directory by the Chrome process; new scheduled tasks, startup entries, or cron jobs created around the time of browser activity.

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 147.0.7727.138 for Windows and Mac, and 147.0.7727.137 for Linux. Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Enterprise administrators should enforce automatic Chrome updates via Group Policy (Windows) or mobile device management solutions. As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites and consider using browser isolation technologies (Chrome Releases, GitHub Advisory).

Community reactions

The vulnerability was part of a large Chrome stable channel update addressing 30 security fixes, which received coverage from security aggregators and Linux distribution maintainers including Debian, Fedora, and openSUSE, who issued downstream Chromium advisories. Kaspersky's threat intelligence portal and Beyond Machines noted the breadth of the April 28, 2026 Chrome update. No significant independent researcher commentary or social media controversy specific to CVE-2026-7356 has been identified, consistent with the absence of a public exploit or active exploitation (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85050CRITICAL9.6
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 03, 2026
CVE-2026-85053HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 03, 2026
CVE-2026-85051HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 03, 2026
CVE-2026-85049HIGH8.8
  • Google Chrome logoGoogle Chrome
  • webkit2gtk3.src
NoYesSep 03, 2026
CVE-2026-85052LOW3.1
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management