CVE-2026-7338: Use after free in Cast
Chromium: CVE-2026-7338 Use after free in Cast
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147.0.7727.137 - Upgrade
Upgrade
Chromium/Cast (via Google Chrome/Edge Chromium-based)to a version that resolves this vulnerability.Fixed in 147.0.7727.138 - Compensating control
Mitigate heap corruption exploitation via malicious network traffic from the local network segment by restricting/isolating network access to the affected client system until it is updated to 147.0.7727.138 or later.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-7363
- CVE-2026-7361
- CVE-2026-7344
- CVE-2026-7343
- CVE-2026-7333
- CVE-2026-7360
- CVE-2026-7359
- CVE-2026-7358
- CVE-2026-7334
- CVE-2026-7357
- CVE-2026-7356
- CVE-2026-7354
- CVE-2026-7353
- CVE-2026-7352
- CVE-2026-7351
- CVE-2026-7350
- CVE-2026-7349
- CVE-2026-7348
- CVE-2026-7335
- CVE-2026-7336
- CVE-2026-7337
- CVE-2026-7347
- CVE-2026-7346
- CVE-2026-7345
- CVE-2026-7342
- CVE-2026-7341
- CVE-2026-7339
- CVE-2026-7340
- CVE-2026-7355
Frequently Asked Questions
What is the severity of CVE-2026-7338?
CVE-2026-7338 is classified as a use after free vulnerability that can potentially allow arbitrary code execution.
How do I fix CVE-2026-7338?
To fix CVE-2026-7338, update Google Chrome to version 147.0.7727.139 or later.
Which versions of Google Chrome are affected by CVE-2026-7338?
CVE-2026-7338 affects Google Chrome versions prior to 147.0.7727.138.
Is Microsoft Edge (Chromium-based) affected by CVE-2026-7338?
Yes, Microsoft Edge (Chromium-based) versions prior to 147.0.3912.98 are affected by CVE-2026-7338.
What are the potential impacts of CVE-2026-7338?
The impacts of CVE-2026-7338 may include unauthorized access to user data and control over affected systems.