CVE-2026-7338

7.5

Google · Chrome

A use after free vulnerability in the Google Chrome Cast component allows unauthenticated attackers on the local network to trigger heap corruption.

Executive summary

A critical use after free vulnerability in Google Chrome allows unauthenticated attackers on the local network to potentially achieve heap corruption and system compromise.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Cast component of Google Chrome. An unauthenticated attacker positioned on the local network segment can send malicious traffic to trigger heap corruption, which may lead to arbitrary code execution or denial of service.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a High severity rating due to the potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the browser process, leading to data theft, unauthorized system access, or significant operational disruption within the organization.

Remediation

Immediate Action: Update all Google Chrome installations to version 147.0.7727.138 or later immediately to incorporate the provided security fix.

Proactive Monitoring: Monitor network traffic for anomalous Cast-related activity or unexpected spikes in browser process crashes which may indicate attempted heap corruption.

Compensating Controls: Implement network segmentation to isolate critical systems and restrict access to the local network segment, effectively limiting the reach of potential local attackers.

Exploitation status

Public Exploit Available: No — no confirmed public exploit exists in the available data.

Analyst recommendation

Given the high severity of this heap corruption vulnerability, organizations must prioritize patching all Chrome instances. While the local network requirement provides a degree of natural mitigation, the risk of remote code execution necessitates prompt action to ensure the security and integrity of the endpoint environment.

More Google CVEs

Sources