Vulnerabilità · 155 giorni fa

Browser Memory Bugs Put Core Components at Risk

Modern browsers are still a broad code-execution target because memory-safety bugs keep turning ordinary page loads into arbitrary code execution paths. The standard response of “update the browser” is necessary, but it does not change the fact that the attack surface spans rendering, media, accessibility, and platform code at once.

Chrome 147 rolls out 30 security fixes, including four critical use-after-free CVEs: CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, and CVE-2026-7343. Mozilla also shipped Firefox updates for memory-safety defects, including critical and high-severity issues in its browser code, with fixes landing in Firefox ESR 140.10.1 and 115.35.1.

The pattern matters more than any single CVE. These fixes show that core browser subsystems keep producing exploitable memory corruption, so exposure is not limited to one feature or one vendor release.

CVE-2026-7363

NVD KEV

CVSS 8.8 HIGH: use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 0.4% (29º percentile).

CVE-2026-7361

NVD KEV

CVSS 8.8 HIGH: use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. EPSS 0.3% (22º percentile).

CVE-2026-7344

NVD KEV

CVSS 8.8 HIGH: use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had… EPSS 0.3% (22º percentile).

CVE-2026-7343

NVD KEV

CVSS 9.8 CRITICAL: use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had… EPSS 0.3% (19º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-04-30

Editions

Storie correlate