Junglewise Threat Intelligence

CVE-2026-7345: Google Chrome sandbox escape in Feedback component

CVE-2026-7345 · Severity: high · CVSS 8.3 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser for accessing the internet and internal applications. A security flaw in the browser's Feedback component could allow a remote attacker to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Feedback component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to escape the browser's sandbox environment by utilizing a specially crafted HTML page. This vulnerability requires user interaction (visiting a malicious site) and is characterized by a high complexity attack vector. Successful exploitation grants the attacker the ability to execute code outside of the restricted browser environment on the host operating system. The issue is resolved in Google Chrome version 147.0.7727.138 and later.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-28: disclosed: Initial publication by Google Chrome team
  • 2026-04-28: patched: Fixed in version 147.0.7727.138

References

Related threats