CVE-2026-7363
CVSS 8.8 HIGH: use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 0.4% (29º percentile).
Vulnerabilità · 155 giorni fa
Modern browsers are still a broad code-execution target because memory-safety bugs keep turning ordinary page loads into arbitrary code execution paths. The standard response of “update the browser” is necessary, but it does not change the fact that the attack surface spans rendering, media, accessibility, and platform code at once.
Chrome 147 rolls out 30 security fixes, including four critical use-after-free CVEs: CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, and CVE-2026-7343. Mozilla also shipped Firefox updates for memory-safety defects, including critical and high-severity issues in its browser code, with fixes landing in Firefox ESR 140.10.1 and 115.35.1.
The pattern matters more than any single CVE. These fixes show that core browser subsystems keep producing exploitable memory corruption, so exposure is not limited to one feature or one vendor release.
CVSS 8.8 HIGH: use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 0.4% (29º percentile).
CVSS 8.8 HIGH: use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. EPSS 0.3% (22º percentile).
CVSS 8.8 HIGH: use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had… EPSS 0.3% (22º percentile).
CVSS 9.8 CRITICAL: use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had… EPSS 0.3% (19º percentile).
1 fonte che coprono questa storia
Chrome 147, Firefox 150 Security Updates Rolling Out
The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.
Part of the PlainSec briefing for 2026-04-30