Junglewise Threat Intelligence

CVE-2026-7342: Google Chrome WebView use after free in Android

CVE-2026-7342 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security vulnerability exists in the WebView component of Google Chrome for Android, which is used by many apps to display web content. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the device. While this code is restricted to a 'sandbox' environment, it could lead to data theft or serve as a stepping stone for further attacks.

Technical details

A use-after-free (UAF) vulnerability exists in the WebView component of Google Chrome for Android prior to version 147.0.7727.138. The flaw is triggered when the browser incorrectly manages memory during the processing of web content, allowing an attacker to reference memory after it has been freed. By enticing a user to load a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the browser's sandbox. Users are advised to update to version 147.0.7727.138 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-28: disclosed: Initial disclosure by Google Chrome team
  • 2026-04-28: patched: Fixed in version 147.0.7727.138
  • 2026-04-28: advisory: NVD publication date

References

Related threats