
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7358 is a use-after-free vulnerability in the Animation component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by Google on March 25, 2026, and publicly disclosed on April 28, 2026, as part of a stable channel update. All versions of Google Chrome prior to 147.0.7727.138 are affected. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and is classified with Chromium security severity: High (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Animation component. A use-after-free condition arises when memory associated with an animation object is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a user to visit a specially crafted HTML page, which triggers the erroneous memory access in the Animation subsystem. The bug was tracked internally as Chromium issue 496285281 and was detected by Google's own security team (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, which constrains but does not eliminate the risk. Within the sandbox, an attacker could access sensitive browser data, steal credentials or session tokens, or potentially chain this vulnerability with a sandbox escape to achieve full system compromise. Confidentiality, integrity, and availability are all rated as High impact, reflecting the severity of arbitrary code execution even in a sandboxed context (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability was reported internally by Google and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.045% (14th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
cmd.exe, /bin/sh, powershell.exe, curl, wget); Chrome renderer processes consuming abnormally high memory or CPU.Google has released a fix in Chrome stable channel version 147.0.7727.137/138 for Windows/Mac and 147.0.7727.137 for Linux, which addresses this vulnerability along with 29 other security issues. Users and administrators should update all Chrome installations to version 147.0.7727.138 or later immediately. Until patching is complete, restrict user access to untrusted or unknown websites and consider deploying endpoint protection or web filtering solutions. No configuration-based workaround is available for this vulnerability (Chrome Releases).
Google's Chrome security team disclosed the vulnerability as part of a large April 28, 2026 stable channel update that addressed 30 security issues, including several Critical-rated use-after-free bugs. Security aggregators such as Kaspersky Threats, Tenable (Nessus), Qualys, and Linux distribution security teams (Debian, Fedora, openSUSE) rapidly published advisories and detection plugins following the disclosure. Community coverage on platforms such as Bluesky and Mastodon noted the breadth of the update. No significant controversy or unusual researcher commentary specific to CVE-2026-7358 has been observed (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."