Junglewise Threat Intelligence

CVE-2026-7338: Google Chrome use after free in Cast

CVE-2026-7338 · Severity: high · CVSS 7.5 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security vulnerability exists in the Cast component of Google Chrome, which is used for streaming media to other devices. An attacker on the same local network could send malicious traffic to trigger a memory error, potentially leading to a browser crash or unauthorized code execution. This could compromise the privacy and security of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the Cast component of Google Chrome. The flaw is triggered when the browser improperly manages memory objects during the processing of network traffic related to casting activities. An attacker located on the same local network segment (Adjacent) can send specially crafted network packets to trigger heap corruption. While the attack requires high complexity (AC:H), a successful exploit could lead to arbitrary code execution within the context of the browser process. The issue is addressed in Chrome version 147.0.7727.138 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-14: disclosed: Reported by researcher Krace
  • 2026-04-28: patched: Fixed in Chrome Stable Channel Update 147.0.7727.138
  • 2026-04-28: advisory

References

Related threats