Junglewise Threat Intelligence

CVE-2026-7350: Google Chrome use after free in WebMIDI

CVE-2026-7350 · Severity: high · CVSS 8.3 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its WebMIDI component could allow a remote attacker to bypass the browser's security 'sandbox' if they have already compromised the initial rendering process. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the WebMIDI component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for MIDI device interactions. An attacker who has already achieved code execution within the renderer process (e.g., via a separate exploit) can leverage this vulnerability to escape the Chrome sandbox and execute arbitrary code on the host system. The attack requires the victim to visit a specially crafted HTML page. This issue is resolved in Google Chrome version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-06: disclosed: Reported to Google internally
  • 2026-04-28: advisory: Vendor advisory published
  • 2026-04-28: patched: Fixed in version 147.0.7727.138

References

Related threats