CVE-2026-7356
8.8Google · Chrome
A use after free vulnerability in the Navigation component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through malicious web content.
Vulnerability
This is a use after free vulnerability (CWE-416) within the browser's navigation logic. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, leading to potential code execution.
Business impact
The ability for an attacker to execute arbitrary code on a user machine poses a severe risk to organizational data integrity and system security. Given the CVSS score of 8.8, this flaw represents a significant threat to confidentiality, integrity, and availability, potentially allowing for the installation of malware or unauthorized access to sensitive browser-stored credentials.
Remediation
Immediate Action: Update all Google Chrome instances to version 147.0.7727.138 or later immediately to resolve the vulnerable navigation component.
Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process spawned by the Chrome executable that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious web-based payloads, and leverage browser-based security policies to restrict navigation to untrusted domains where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of browser-based code execution, administrators must prioritize the deployment of the Chrome update across all workstations. The potential for total system compromise necessitates swift action to ensure that the browser navigation logic is secured against this high-severity flaw.