Description
Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug (CWE‑416) exists in the Views component of Google Chrome on macOS prior to version 147.0.7727.138. When a crafted HTML page is rendered, an attacker can trigger heap corruption that may lead to arbitrary code execution. This vulnerability is identified as CWE‑416 and CWE‑825. The Chromium security team has rated the severity of this issue as high, indicating that successful exploitation allows an attacker to run code with user privileges or higher within the browser process.

Affected Systems

The vulnerability affects Google Chrome on macOS versions prior to 147.0.7727.138. The CVE description does not mention Windows or Linux; therefore, those platforms are not known to be impacted by this use‑after‑free flaw.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity classification, and the EPSS score is not available. The issue is not yet cataloged in the CISA KEV database. Exploitation requires a crafted HTML page; a remote attacker could lure a user to such a page, which may lead to code execution on the client machine. Due to the high severity and absence of a publicly available EPSS score, the exploitation probability remains uncertain but warrants immediate remediation.

Generated by OpenCVE AI on April 29, 2026 at 14:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 147.0.7727.138 or later on all macOS devices
  • Enable automatic updates to receive security patches promptly
  • Avoid navigating to untrusted web pages or links until the browser update is installed

Generated by OpenCVE AI on April 29, 2026 at 14:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6239-1 chromium security update
History

Thu, 30 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 29 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Views on macOS Enables Potential Remote Exploit chromium-browser: Use after free in Views
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 29 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Views on macOS Enables Potential Remote Exploit

Wed, 29 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-30T03:55:50.767Z

Reserved: 2026-04-28T20:02:32.960Z

Link: CVE-2026-7334

cve-icon Vulnrichment

Updated: 2026-04-29T18:24:10.443Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-28T23:16:20.963

Modified: 2026-04-30T18:29:37.647

Link: CVE-2026-7334

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-28T00:00:00Z

Links: CVE-2026-7334 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:45:13Z

Weaknesses