CVE-2026-7357

7.5

Google · Chrome

A use after free vulnerability in the GPU component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome could allow a remote attacker to achieve heap corruption and potentially execute arbitrary code.

Vulnerability

The flaw exists within the GPU component, where a use after free condition permits a remote attacker who has compromised the renderer process to induce heap corruption. This requires user interaction, as the attacker must entice a user to visit a crafted HTML page.

Business impact

The potential for heap corruption presents a significant risk, as it may lead to arbitrary code execution or total system compromise if successfully exploited. Given the CVSS score of 7.5, this vulnerability is classified as High severity, necessitating prompt attention to prevent unauthorized access or system instability within the enterprise environment.

Remediation

Immediate Action: Update Google Chrome to version 147.0.7727.138 or later to incorporate the vendor security patch.

Proactive Monitoring: Monitor browser-based traffic for unusual patterns and review endpoint detection logs for signs of anomalous renderer process activity.

Compensating Controls: Deploy browser security policies that restrict navigation to untrusted sites and ensure that endpoint security solutions are configured to detect exploit attempts targeting browser memory corruption.

Exploitation status

Public Exploit Available: No (Exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk to end-user workstations and requires immediate remediation. Administrators should prioritize the deployment of the latest Chrome update across all managed endpoints to neutralize the threat of heap corruption and potential remote code execution.

More Google CVEs

Sources