CVE-2026-7358
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-7358 is a use-after-free vulnerability in the Animation component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by Google on March 25, 2026, and publicly disclosed on April 28, 2026, as part of a stable channel update. All versions of Google Chrome prior to 147.0.7727.138 are affected. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and is classified with Chromium security severity: High (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Animation component. A use-after-free condition arises when memory associated with an animation object is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a user to visit a specially crafted HTML page, which triggers the erroneous memory access in the Animation subsystem. The bug was tracked internally as Chromium issue 496285281 and was detected by Google's own security team (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, which constrains but does not eliminate the risk. Within the sandbox, an attacker could access sensitive browser data, steal credentials or session tokens, or potentially chain this vulnerability with a sandbox escape to achieve full system compromise. Confidentiality, integrity, and availability are all rated as High impact, reflecting the severity of arbitrary code execution even in a sandboxed context (GitHub Advisory, Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability was reported internally by Google and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.045% (14th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.138 on Windows, Mac, or Linux using browser fingerprinting or social engineering.
  2. Craft malicious HTML page: Develop an HTML page containing JavaScript or CSS animation sequences designed to trigger a use-after-free condition in Chrome's Animation component (Chromium issue 496285281). The specific trigger involves manipulating animation object lifecycles to cause premature memory deallocation followed by a dangling pointer dereference.
  3. Deliver the page: Host the crafted HTML page on an attacker-controlled server and lure the target user to visit it via phishing, malvertising, or a compromised website.
  4. Trigger the vulnerability: When the victim loads the page in a vulnerable Chrome version, the Animation component processes the malicious content, triggering the use-after-free condition.
  5. Execute arbitrary code: By controlling the freed memory region (e.g., via heap grooming techniques), the attacker redirects execution to attacker-controlled code, achieving arbitrary code execution within the Chrome sandbox.
  6. Post-exploitation: From within the sandbox, the attacker may attempt to access browser-stored credentials, cookies, or session data, or chain with a sandbox escape vulnerability for broader system access (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome browser process to unknown or suspicious IP addresses following a web page visit; HTTP/HTTPS requests to newly registered or low-reputation domains serving HTML/JavaScript content.
  • Process: Unusual child processes spawned by the Chrome renderer process (e.g., cmd.exe, /bin/sh, powershell.exe, curl, wget); Chrome renderer processes consuming abnormally high memory or CPU.
  • Logs: Browser crash reports or minidumps referencing the Animation component; Chrome crash logs indicating heap corruption or access violations in animation-related code paths.
  • File System: Unexpected files written to the user's profile directory or temp directories by the Chrome process; new or modified browser extensions installed without user action.

Mitigation and workarounds

Google has released a fix in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, which addresses this vulnerability along with 29 other security issues. Users and administrators should update all Chrome installations to version 147.0.7727.138 or later immediately. Until patching is complete, restrict user access to untrusted or unknown websites and consider deploying endpoint protection or web filtering solutions. No configuration-based workaround is available for this vulnerability (Chrome Releases).

Community reactions

Google's Chrome security team disclosed the vulnerability as part of a large April 28, 2026 stable channel update that addressed 30 security issues, including several Critical-rated use-after-free bugs. Security aggregators such as Kaspersky Threats, Tenable (Nessus), Qualys, and Linux distribution security teams (Debian, Fedora, openSUSE) rapidly published advisories and detection plugins following the disclosure. Community coverage on platforms such as Bluesky and Mastodon noted the breadth of the update. No significant controversy or unusual researcher commentary specific to CVE-2026-7358 has been observed (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76023HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76022HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesAug 20, 2026
CVE-2026-76021HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76019HIGH8.1
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76020HIGH7.5
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management