CVE-2026-7338

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

30 Apr 2026, 18:28

Type Values Removed Values Added
References () https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html - () https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html - Vendor Advisory
References () https://issues.chromium.org/issues/502449857 - () https://issues.chromium.org/issues/502449857 - Permissions Required
CPE cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Microsoft
Google
Linux linux Kernel
Linux
Google chrome
Microsoft windows
Apple macos
Apple

30 Apr 2026, 15:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

28 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 23:16

Updated : 2026-04-30 18:28


NVD link : CVE-2026-7338

Mitre link : CVE-2026-7338

CVE.ORG link : CVE-2026-7338


JSON object : View

Products Affected

google

  • chrome

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-416

Use After Free