Junglewise Threat Intelligence

CVE-2026-7361: Google Chrome use after free in iOS

CVE-2026-7361 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the iOS version of the browser could allow a remote attacker to compromise a user's device if they are tricked into visiting a specially crafted website. This could lead to unauthorized access to sensitive data or the ability to execute malicious code on the device.

Technical details

A use-after-free (UAF) vulnerability exists in the iOS implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could allow for arbitrary code execution within the context of the browser process. The issue is resolved in version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-16: other: Reported to Google
  • 2026-04-28: advisory: Vendor advisory published
  • 2026-04-28: patched: Fixed in version 147.0.7727.138

References

Related threats