CVE-2026-7361Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-29: 4Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 304-29
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 Critical Chrome Alert: A new batch of CVEs, including CVE-2026-7363 (Canvas UAF) and CVE-2026-7361 (iOS Heap Corruption), allows remote code execution via crafted HTML pages. Update to 147.0.7727.138+ immediately to patch these sandbox escapes. CVE-2026-7363: https://nvd.nist.gov/vuln/detail/CVE-2026-7363 CVE-2026-7361: https://nvd.nist.gov/vuln/detail/CVE-2026-7361

    Post summary

    The post announces recent Chrome CVEs that enable remote code execution via crafted HTML, stresses an immediate update to patch the sandbox escapes, and provides brief technical details of the vulnerabilities.

    1003170
    1.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-7361) https://vuldb.com/vuln/360084

    Post summary

    A newly disclosed Chrome vulnerability (CVE-2026-7361) with increased severity is reported, as cited on VulDB.

    0000167
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7361 Use After Free in Google Chrome Prior to 147.0.7727.138 on... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7361 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet notes CVE-2026-7361 as a use‑after‑free flaw in Chrome versions before 147.0.7727.138, linking to a vulnerability details page but providing no PoC, patch, or exploitation evidence.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7361 Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur… https://www.cve.org/CVERecord?id=CVE-2026-7361

    Post summary

    CVE‑2026‑7361 describes a use‑after‑free vulnerability affecting iOS Chrome versions prior to 147.0.7727.138, allowing a remote attacker to trigger heap corruption via a crafted HTML page.

    00000166
    57.3K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more