Junglewise Threat Intelligence

CVE-2026-7356: Google Chrome use after free in Navigation

CVE-2026-7356 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the browser's navigation component could allow an attacker to execute malicious code on a user's computer if they visit a specially crafted website. This could lead to the theft of sensitive data, unauthorized access to the system, or a complete compromise of the user's device.

Technical details

A use-after-free (UAF) vulnerability exists in the Navigation component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during page navigation, allowing a remote attacker to exploit the memory corruption via a specifically crafted HTML page. This is a network-based attack that requires user interaction (visiting a malicious site) but no prior authentication. Successful exploitation can lead to arbitrary code execution (ACE) within the context of the browser process. The issue is resolved in Google Chrome version 147.0.7727.138 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-30: other: Reported to Chromium by Google researchers
  • 2026-04-28: advisory: Google Chrome stable channel update published
  • 2026-04-28: disclosed: NVD publication date

References

Related threats