CVE-2026-7333
A critical vulnerability in Google Chrome’s GPU component allows a remote attacker to escape the browser sandbox by loading a specially crafted web page. The flaw is a use‑after‑free bug that can be triggered over the network, potentially giving the attacker full control of the victim’s machine.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome users on any platform (Windows, macOS, Linux) using a version older than 147.0.7727.138 are affected.
Real-world impact
An attacker could run arbitrary code on the victim’s computer, potentially taking full control of the system.
Why this severity
The CVSS score of 9.6 reflects the high impact on confidentiality, integrity, and availability, the low effort required to exploit the use‑after‑free bug, and the ability to escape the browser sandbox.
What to do about it
- 01Upgrade Google Chrome to version 147.0.7727.138 or later.
- 02Restart the browser.
NVD-referenced vendor advisory
Timeline
- Apr 28, 2026 · Apr 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/04/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/493955227permissions required