CVE-2026-7358

8.8

Google · Chrome

A use after free vulnerability in the Google Chrome Animation component allows a remote attacker to achieve arbitrary code execution via a specially crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code on affected systems via malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Animation component of Google Chrome. The flaw allows an unauthenticated remote attacker to execute arbitrary code within the browser sandbox by enticing a user to navigate to a crafted HTML page.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it enables remote code execution on end user workstations. With a CVSS score of 8.8, this flaw represents a high risk of system compromise, potential data theft, and the installation of persistent malware, which can lead to significant operational disruption and data breaches.

Remediation

Immediate Action: Update all Google Chrome installations to version 147.0.7727.138 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Monitor endpoint security logs for unusual browser process behavior, such as unexpected crashes or unauthorized child process spawning originating from the Chrome browser.

Compensating Controls: Ensure that users are operating with the least privilege necessary and employ endpoint protection platforms (EPP) that can detect and block malicious memory manipulation attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the ability for remote attackers to trigger code execution via standard web browsing, this vulnerability requires urgent attention. IT administrators should prioritize the deployment of the browser update across all enterprise environments to neutralize the risk of exploitation.

More Google CVEs

Sources