CVE-2026-7350

8.3

Google · Chrome

A use after free vulnerability in the WebMIDI component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox, posing a severe risk to system integrity.

Vulnerability

This is a use after free flaw (CWE-416) within the WebMIDI component. An unauthenticated remote attacker can exploit this via a crafted HTML page to compromise the renderer process and subsequently perform a sandbox escape.

Business impact

The ability to escape the browser sandbox grants an attacker elevated control over the underlying operating system. Given the CVSS score of 8.3, this vulnerability represents a high risk of total system compromise, potentially leading to unauthorized data access, malware installation, or persistent system-wide infection.

Remediation

Immediate Action: Update all Google Chrome installations to version 147.0.7727.138 or later to incorporate the vendor-supplied security patch.

Proactive Monitoring: Review security logs for suspicious browser process activity or unexpected crashes associated with MIDI-enabled content.

Compensating Controls: While no direct WAF mitigation exists for browser-side sandbox escapes, users should exercise caution with untrusted websites and consider disabling unnecessary browser extensions.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of a sandbox escape necessitates immediate action. IT administrators must prioritize the deployment of the Chrome update across all endpoints to mitigate the risk of remote code execution and host-level compromise. Failure to patch this vulnerability leaves systems exposed to sophisticated web-based attacks that can bypass standard browser security protections.

More Google CVEs

Sources