CVE-2026-7356

8.8

Google · Chrome

A use after free vulnerability in the Navigation component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) within the browser's navigation logic. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, leading to potential code execution.

Business impact

The ability for an attacker to execute arbitrary code on a user machine poses a severe risk to organizational data integrity and system security. Given the CVSS score of 8.8, this flaw represents a significant threat to confidentiality, integrity, and availability, potentially allowing for the installation of malware or unauthorized access to sensitive browser-stored credentials.

Remediation

Immediate Action: Update all Google Chrome instances to version 147.0.7727.138 or later immediately to resolve the vulnerable navigation component.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process spawned by the Chrome executable that may indicate exploitation attempts.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious web-based payloads, and leverage browser-based security policies to restrict navigation to untrusted domains where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of browser-based code execution, administrators must prioritize the deployment of the Chrome update across all workstations. The potential for total system compromise necessitates swift action to ensure that the browser navigation logic is secured against this high-severity flaw.

More Google CVEs

Sources