CVE-2026-7333Disclosure(apple / chrome)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-29); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-29: 3Mentions · 2026-05-01: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-29: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 104-2905-0105-05
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-293
Disclosure3
2026-05-011
Patch1
2026-05-051
General1
Full discourse5 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-7333)[$16000][493955227][viz]Modifying surface activation group vector while iterating through the existing entries -> ... -> UAF https://chromium-review.googlesource.com/c/chromium/src/+/7707244 Reported by c6eed09fc8b174b0f3eebedcceb1e792

    Post summary

    A new Chrome vulnerability (CVE‑2026‑7333) is disclosed as a use‑after‑free in the surface activation group vector, with a reference to the code review but no exploit or mitigation details.

    00014112.7K
    5.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7333 Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium secu… https://www.cve.org/CVERecord?id=CVE-2026-7333

    Post summary

    The post announces the CVE‑2026‑7333 GPU use‑after‑free in Chrome that could allow a sandbox escape via a crafted HTML page; it offers technical details but does not mention PoC, exploitation, or patches.

    00010152
    57.3K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-7333 | Chromium: CVE-2026-7333 Use after free in GPU | RAHSI Framework™ https://www.aakashrahsi.online/post/cve-2026-7333 https://t.co/tXlAK0zGCS

    Post summary

    The post announces CVE-2026-7333 as a use‑after‑free vulnerability in Chromium’s GPU implementation, but offers no details on PoC, exploit code, or mitigation.

    0000029
    1 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Chromium GPU use-after-free (CVE-2026-7333): escape the sandbox via a crafted HTML page. Great, so the “safe browser” is only as safe as your auto-update. Patch today. https://windowsforum.com/threads/cve-2026-7333-chromium-gpu-use-after-free-patch-chrome-and-edge-on-windows.416064/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurityUpdates #BrowserSandboxEscape #Cve20267333 #ChromiumGpu https://t.co/j5r2WeUkrq

    Post summary

    The tweet announces the CVE‑2026‑7333 use‑after‑free flaw in Chromium, highlighting sandbox escape via crafted HTML and urges users to apply the patch, but it does not provide PoC or exploit code.

    0000037
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7333 Use After Free in GPU in Google Chrome Prior to 147.0.7727.138 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7333

    Post summary

    The text introduces CVE-2026-7333 as a Use After Free vulnerability in Google Chrome's GPU prior to version 147.0.7727.138, but provides no evidence of exploits, PoCs, patches, or active attacks.

    0000060
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more