Junglewise Threat Intelligence

CVE-2026-7352: Google Chrome use after free in Media

CVE-2026-7352 · Severity: high · CVSS 8.3 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security flaw in its media handling component could allow a remote attacker to bypass the browser's security 'sandbox' if they have already compromised the initial rendering process. This could lead to unauthorized access to the underlying Android operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of media content. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this vulnerability via a specially crafted HTML page to escape the sandbox and gain broader access to the system. This vulnerability was addressed in version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-02: disclosed: Reported to Chromium by Google researchers
  • 2026-04-28: patched: Fixed in stable channel update 147.0.7727.138
  • 2026-04-28: advisory

References

Related threats