Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-7333 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-04-29 |
| Vendor | |
| Product | Chrome |
| CVSS Score | 9.6 (critical) |
| EPSS Score | 0.0% (percentile: 10%) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Required Actions
Update Google Chrome to version 147.0.7727.138 or newer on all workstations immediately. In enterprise environments, force a browser restart so the update takes effect. Consider enabling Chrome Browser Cloud Management auto-update policies and inform users they need to close all browser tabs.
Who Is Affected?
This vulnerability affects Chrome by Google. Check whether your organization uses Google Chrome (and Chromium-based browsers) and roll out the update to version 147.0.7727.138 or newer.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
