Junglewise Threat Intelligence

CVE-2026-7358: Google Chrome use after free in Animation

CVE-2026-7358 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security vulnerability exists in the Google Chrome web browser's animation component. By tricking a user into visiting a specially crafted website, an attacker could potentially execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized access to data or further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Animation component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of web animations. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page, leading to memory corruption. Successful exploitation allows for arbitrary code execution within the context of the Chrome renderer sandbox. The issue is resolved in Google Chrome version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-25: other: Reported to Chrome by Google researchers
  • 2026-04-28: patched: Fixed in stable channel update 147.0.7727.138
  • 2026-04-28: disclosed: Public advisory published

References

Related threats