CVE-2026-7350
8.3Google · Chrome
A use after free vulnerability in the WebMIDI component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox, posing a severe risk to system integrity.
Vulnerability
This is a use after free flaw (CWE-416) within the WebMIDI component. An unauthenticated remote attacker can exploit this via a crafted HTML page to compromise the renderer process and subsequently perform a sandbox escape.
Business impact
The ability to escape the browser sandbox grants an attacker elevated control over the underlying operating system. Given the CVSS score of 8.3, this vulnerability represents a high risk of total system compromise, potentially leading to unauthorized data access, malware installation, or persistent system-wide infection.
Remediation
Immediate Action: Update all Google Chrome installations to version 147.0.7727.138 or later to incorporate the vendor-supplied security patch.
Proactive Monitoring: Review security logs for suspicious browser process activity or unexpected crashes associated with MIDI-enabled content.
Compensating Controls: While no direct WAF mitigation exists for browser-side sandbox escapes, users should exercise caution with untrusted websites and consider disabling unnecessary browser extensions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of a sandbox escape necessitates immediate action. IT administrators must prioritize the deployment of the Chrome update across all endpoints to mitigate the risk of remote code execution and host-level compromise. Failure to patch this vulnerability leaves systems exposed to sophisticated web-based attacks that can bypass standard browser security protections.