Description
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-28
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

CVE‑2026‑7342 is a use‑after‑free vulnerability in the WebView component of Google Chrome on Android. The flaw allows a remote attacker to craft a malicious HTML page that triggers the freed memory to be accessed again, resulting in execution of arbitrary code inside the sandbox. The vulnerability is classified as high severity.

Affected Systems

The affected product is Google Chrome WebView on Android, specifically versions earlier than 147.0.7727.138. Devices running these versions can be impacted by a maliciously crafted HTML page delivered over the network.

Risk and Exploitability

The attack vector is remote, requiring an attacker to deliver a specially formed HTML page to a vulnerable device. While exploitation has not been confirmed in the wild, the absence of an EPSS score suggests limited observable activity and the weakness is not listed in CISA KEV. The vulnerability remains a significant risk if the device is connected to potentially hostile networks, given its high severity.

Generated by OpenCVE AI on April 29, 2026 at 02:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 147.0.7727.138 or newer, which resolves the use‑after‑free flaw (CWE‑416) in the WebView component.
  • Reboot the device or restart all affected services to ensure the patched WebView is loaded.
  • If an immediate update is not possible, restrict WebView usage by configuring the application to block untrusted or external HTML content, or disable external links that could serve malicious pages, thereby limiting exposure to the CWE‑416 use‑after‑free vulnerability.

Generated by OpenCVE AI on April 29, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome WebView Allows Remote Code Execution

Wed, 29 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-28T22:36:07.295Z

Reserved: 2026-04-28T20:02:37.760Z

Link: CVE-2026-7342

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-28T23:16:21.787

Modified: 2026-04-28T23:16:21.787

Link: CVE-2026-7342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T02:15:47Z

Weaknesses