CVE-2026-7338
published 2026-04-28CVE-2026-7338: Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via…
high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 147.0.7727.138 | 147.0.7727.138 | |
| chrome | >= 147.0.7727.138 < 147.0.7727.138 | 147.0.7727.138 | |
| chrome_desktop | — | — |
GHSA
GHSA-c7m2-hhfc-83rm: Use after free in Cast in Google Chrome prior to 147
ghsa_unreviewed·2026-04-29
CVE-2026-7338 [HIGH] CWE-416 GHSA-c7m2-hhfc-83rm: Use after free in Cast in Google Chrome prior to 147
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Red Hat
chromium-browser: Use after free in Cast
vendor_redhat·2026-04-28·CVSS 8.8
CVE-2026-7338 [HIGH] CWE-825 chromium-browser: Use after free in Cast
chromium-browser: Use after free in Cast
An use after free flaw was found in the Cast component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=502449857
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-7338
vendor_chrome·2026-04-28
CVE-2026-7338 [HIGH] Stable Channel Update for Desktop: CVE-2026-7338
Stable Channel Update for Desktop
CVE-2026-7338: Use after free in Cast. Reported by Krace on 2026-04-14 [TBD][ 503889643 ] High CVE-2026-7342: Use after free in WebView
Reported by Google on 2026-04-17 [TBD][ 504586599 ] High CVE-2026-7341: Use after free in WebRTC
Severity: high
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-
bugzilla·2026-04-29
CVE-2026-7333 [CRITICAL] CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-
CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-2026-7347 ... chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-
bugzilla·2026-04-29
CVE-2026-7333 [CRITICAL] CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-
CVE-2026-7333 CVE-2026-7334 CVE-2026-7335 CVE-2026-7336 CVE-2026-7337 CVE-2026-7338 CVE-2026-7339 CVE-2026-7340 CVE-2026-7341 CVE-2026-7342 CVE-2026-7343 CVE-2026-7344 CVE-2026-7345 CVE-2026-7346 CVE-2026-7347 ... chromium: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7338 chromium-browser: Use after free in Cast
bugzilla·2026-04-28
CVE-2026-7338 [HIGH] CVE-2026-7338 chromium-browser: Use after free in Cast
CVE-2026-7338 chromium-browser: Use after free in Cast
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
2026-04-28
Published