Description
Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-28
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution via heap corruption in Chrome for macOS
Action: Patch Immediately
AI Analysis

Impact

A use‑after‑free bug (CWE‑416) exists in the Views component of Google Chrome on macOS prior to version 147.0.7727.138. When a crafted HTML page is rendered, an attacker can trigger heap corruption that may lead to arbitrary code execution. The Chromium security team has rated the severity of this issue as high, indicating that successful exploitation allows an attacker to run code with user privileges or higher within the browser process.

Affected Systems

The vulnerability affects Google Chrome on macOS versions prior to 147.0.7727.138. The CVE description does not mention Windows or Linux; therefore, those platforms are not known to be impacted by this use‑after‑free flaw.

Risk and Exploitability

The EPSS score is not available, but the vulnerability is listed as high severity and is not yet cataloged in the CISA KEV database. Exploitation requires a crafted HTML page; a remote attacker could lure a user to such a page, leading to potential code execution on the client machine. The lack of an EPSS score means the probability of exploitation is uncertain, yet the high severity and potential to break out of the browser sandbox justify urgent remediation.

Generated by OpenCVE AI on April 29, 2026 at 02:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 147.0.7727.138 or later on all macOS devices
  • Enable automatic updates to receive security patches promptly
  • Avoid navigating to untrusted web pages or links until the browser update is installed

Generated by OpenCVE AI on April 29, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Views on macOS Enables Potential Remote Exploit

Wed, 29 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-28T22:35:56.997Z

Reserved: 2026-04-28T20:02:32.960Z

Link: CVE-2026-7334

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-28T23:16:20.963

Modified: 2026-04-28T23:16:20.963

Link: CVE-2026-7334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T02:45:35Z

Weaknesses