Junglewise Threat Intelligence

CVE-2026-7334: Google Chrome use after free in Views

CVE-2026-7334 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the 'Views' component on macOS versions could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the theft of sensitive data, unauthorized access to the user's system, or application crashes.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome on macOS. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing a remote attacker to induce heap corruption. An attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution within the browser's sandbox or a denial-of-service condition. The issue was addressed in version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-26: disclosed: Reported by Batuhan Eşref KOÇ
  • 2026-04-28: patched: Fixed in version 147.0.7727.138
  • 2026-04-28: advisory

References

Related threats