Description
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑7342 is a use‑after‑free vulnerability in the WebView component of Google Chrome on Android. The flaw allows a remote attacker to craft a malicious HTML page that triggers the freed memory to be accessed again, resulting in execution of arbitrary code inside the sandbox. The vulnerability is classified as high severity.

Affected Systems

The affected product is Google Chrome WebView on Android, specifically versions earlier than 147.0.7727.138. Devices running these versions can be impacted by a maliciously crafted HTML page delivered over the network.

Risk and Exploitability

The attack vector is remote, requiring an attacker to deliver a specially formed HTML page to a vulnerable device. While exploitation has not been confirmed in the wild, the EPSS score is < 1% and the vulnerability is not listed in CISA KEV. With a CVSS score of 8.8, the flaw is considered high, and devices running earlier versions remain highly susceptible if exposed to hostile networks.

Generated by OpenCVE AI on April 29, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 147.0.7727.138 or newer, which resolves the use‑after‑free flaw (CWE‑416) in the WebView component.
  • Reboot the device or restart all affected services to ensure the patched WebView is loaded.
  • If an immediate update is not possible, restrict WebView usage by configuring the application to block untrusted or external HTML content, or disable external links that could serve malicious pages, thereby limiting exposure to the CWE‑416 use‑after‑free vulnerability.

Generated by OpenCVE AI on April 29, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6239-1 chromium security update
History

Thu, 30 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 29 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 29 Apr 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Wed, 29 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome WebView Allows Remote Code Execution chromium-browser: Use after free in WebView
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Wed, 29 Apr 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome WebView Allows Remote Code Execution

Wed, 29 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-01T03:55:38.938Z

Reserved: 2026-04-28T20:02:37.760Z

Link: CVE-2026-7342

cve-icon Vulnrichment

Updated: 2026-04-29T12:42:13.658Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-28T23:16:21.787

Modified: 2026-04-30T16:36:27.660

Link: CVE-2026-7342

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-28T00:00:00Z

Links: CVE-2026-7342 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:15:16Z

Weaknesses