CVE-2026-7363Disclosure(apple / chrome)

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 4 mentions (2026-04-29); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-04-29: 4Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-09: 1Mentions · 2026-06-14: 1PoC Mentioned / Linked · 2026-05-04: 1Active Exploitation · 2026-04-29: 1Patch / Workaround · 2026-04-29: 2Patch / Workaround · 2026-06-14: 1Technical Details · 2026-04-29: 4Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-06-14: 104-2905-0405-0505-0906-14
Signal classification4 categories
Disclosure
562.5%
Active Exploitation
112.5%
Patch
112.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-294
Active Exploitation1Disclosure2Patch1
2026-05-041
Disclosure1
2026-05-051
Disclosure1
2026-05-091
General1
2026-06-141
Disclosure1
Full discourse8 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 Critical Chrome Alert: A new batch of CVEs, including CVE-2026-7363 (Canvas UAF) and CVE-2026-7361 (iOS Heap Corruption), allows remote code execution via crafted HTML pages. Update to 147.0.7727.138+ immediately to patch these sandbox escapes. CVE-2026-7363: https://nvd.nist.gov/vuln/detail/CVE-2026-7363 CVE-2026-7361: https://nvd.nist.gov/vuln/detail/CVE-2026-7361

    Post summary

    The tweet announces critical CVEs CVE-2026-7363 and CVE-2026-7361, details the remote code execution vectors, and urges an immediate browser update to patch the vulnerabilities.

    1003170
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    00:11 UTC: CVE-2026-7363 disclosed. Thirty Patches, Four Craters: Chrome 147's Critical Use-After-Free Cluster and What Happens When AI Finds Bugs Faster Th

    Post summary

    CVE-2026-7363, a critical use‑after‑free flaw in Chrome 147, was disclosed at 00:11 UTC; thirty patches have been issued to address the issue, though no PoC, exploit code, or evidence of active exploitation is provided.

    1000037
    267 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 90% of vulnerabilities from past week, CVE-2026-7363 has 9 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet highlights that CVE-2026-7363 has been widely reported, pointing to an external link for further information, but offers no technical or actionable details.

    0000032
    71 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-7363: Use-After-Free Bug in Google Chrome Canvas - What It Means for Your Business and How to Respond https://hubs.li/Q04fsKww0

    Post summary

    The text announces CVE-2026-7363 as a use‑after‑free vulnerability in Chrome’s canvas API, discussing its business implications but offering no evidence of exploitation or existing patches.

    0000052
    29 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-7363 | Chromium: CVE-2026-7363 Use after free in Canvas | Rahsi Framework™ https://www.aakashrahsi.online/post/cve-2026-7363 https://t.co/uItcAUVyWe

    Post summary

    The tweet announces CVE-2026-7363, a use‑after‑free flaw in Chromium’s Canvas, linking to a post that likely contains a proof of concept, but does not mention any patch or active exploitation.

    0000033
    1 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    In-the-wild exploitation of CVE-2026-7363 lets attackers execute remote code via Google Chrome's Canvas on Linux and ChromeOS. Patch now to prevent full compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #DataBreach #Google #Linux https://t.co/UQMIhPcKQI

    Post summary

    The tweet reports that CVE-2026-7363 is actively exploited in the wild, allowing remote code execution on Chrome with Canvas on Linux/ChromeOS, and urges users to apply the patch.

    0000048
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7363 Use After Free in Canvas in Google Chrome Prior to 147.0.7727.138 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7363

    Post summary

    The post discloses CVE-2026-7363, a use‑after‑free vulnerability in Chrome’s Canvas feature that affects versions before 147.0.7727.138.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7363 Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … https://www.cve.org/CVERecord?id=CVE-2026-7363

    Post summary

    A new CVE-2026-7363 has been disclosed: a use‑after‑free in Chrome’s Canvas that allows remote code execution inside a sandbox on Linux/ChromeOS versions prior to 147.0.7727.138. No PoC, exploit, or patch information is mentioned.

    00000151
    57.3K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more