Junglewise Threat Intelligence

CVE-2026-7357: Google Chrome use after free in GPU

CVE-2026-7357 · Severity: high · CVSS 7.5 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security vulnerability has been identified in the Google Chrome web browser's graphics processing component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing them to execute unauthorized commands or crash the browser. This could lead to the theft of sensitive information or a disruption of the user's browsing session.

Technical details

A use-after-free vulnerability exists in the GPU component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during graphics processing, specifically after a renderer process has already been compromised. A remote attacker can exploit this by enticing a user to load a malicious HTML page, leading to heap corruption. This could allow the attacker to escape the renderer sandbox or achieve arbitrary code execution within the context of the GPU process. The issue is resolved in Chrome version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-27: disclosed: Reported by Google internal researchers
  • 2026-04-28: patched: Fixed in stable channel update 147.0.7727.138
  • 2026-04-28: advisory

References

Related threats