CVE-2026-7352
8.3Google · Chrome
A use after free vulnerability in the Media component of Google Chrome on Android allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Executive summary
Google Chrome on Android is affected by a high-severity use after free vulnerability that could allow a remote attacker to escape the browser sandbox and execute arbitrary code.
Vulnerability
This is a use after free flaw within the Media component, which can be triggered by an unauthenticated attacker via a specifically crafted HTML page to achieve a sandbox escape.
Business impact
The ability to escape the browser sandbox represents a significant risk to organizational endpoint security. Successful exploitation could lead to full system compromise, unauthorized data access, and potential lateral movement within the network. Given the CVSS score of 8.3, this vulnerability is classified as High and requires immediate attention to prevent potential exploitation.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 147.0.7727.138 or later immediately.
Proactive Monitoring: Monitor mobile device management (MDM) logs to ensure all managed browsers are updated and check for anomalous browser crashes, which may indicate exploitation attempts.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to provide an additional layer of defense against malicious applications or content.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with the potential for sandbox escape, makes patching a top priority for all administrators managing Android endpoints. Organizations should prioritize the deployment of the Chrome update to all mobile assets to mitigate the risk of remote code execution and unauthorized system access.