Junglewise Threat Intelligence

CVE-2026-7363: Google Chrome use after free in Canvas

CVE-2026-7363 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google ChromeOS, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome and ChromeOS are affected by a critical security flaw in the Canvas component, which handles 2D and 3D graphics in the browser. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's device. While the attack is limited by the browser's security sandbox, it could lead to unauthorized access to data or further compromise of the system.

Technical details

A use-after-free (UAF) vulnerability exists in the Canvas component of Google Chrome on Linux and ChromeOS. The flaw is triggered when the browser incorrectly manages memory for graphics rendering objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the browser's sandbox. The vulnerability is addressed in version 147.0.7727.138 and later.

Affected products

  • Google Chrome prior to 147.0.7727.138
  • Google ChromeOS prior to 147.0.7727.138

Timeline

  • 2026-03-19: disclosed: Reported by external researcher heapracer
  • 2026-04-28: patched: Stable channel update released
  • 2026-04-28: advisory

References

Related threats