CVE-2026-7360
published 2026-04-28CVE-2026-7360: Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer…
low3.1CVSS 3.1
AVNACHPRNUIRSUCLINAN
Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 147.0.7727.138 | 147.0.7727.138 | |
| chrome | >= 147.0.7727.138 < 147.0.7727.138 | 147.0.7727.138 | |
| chrome_desktop | — | — |
Chrome
Stable Channel Update for Desktop: CVE-2026-7343
vendor_chrome·2026-04-28
CVE-2026-7343 [CRITICAL] Stable Channel Update for Desktop: CVE-2026-7343
Stable Channel Update for Desktop
CVE-2026-7343: Use after free in Views. Reported by Google on 2026-04-17 [$16000][ 493955227 ] High CVE-2026-7333: Use after free in GPU
Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-19 [TBD][ 495852034 ] High CVE-2026-7360: Insufficient validation of untrusted input in Compositing
Severity: critical
Red Hat
chromium-browser: Insufficient validation of untrusted input in Compositing
vendor_redhat·2026-04-28·CVSS 8.7
CVE-2026-7360 [HIGH] CWE-1173 chromium-browser: Insufficient validation of untrusted input in Compositing
chromium-browser: Insufficient validation of untrusted input in Compositing
An insufficient validation of untrusted input flaw was found in the Compositing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=495852034
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
GHSA-w4x3-2225-f6c3: Insufficient validation of untrusted input
ghsa_unreviewed·2026-04-29
CVE-2026-7360 [LOW] CWE-20 GHSA-w4x3-2225-f6c3: Insufficient validation of untrusted input
Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
2026-04-28
Published