Google Chrome < 147.0.7727.137 Multiple Vulnerabilities

critical Nessus Plugin ID 310864

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 147.0.7727.137. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_04_stable-channel-update-for-desktop_28 advisory.

- Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity:
Critical) (CVE-2026-7363)

- Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-7361)

- Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-7344)

- Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical) (CVE-2026-7343)

- Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) (CVE-2026-7333)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 147.0.7727.137 or later.

See Also

http://www.nessus.org/u?3bfbde0c

https://crbug.com/494352590

https://crbug.com/493221953

https://crbug.com/503419515

https://crbug.com/503645680

https://crbug.com/493955227

https://crbug.com/495852034

https://crbug.com/496284494

https://crbug.com/496285281

https://crbug.com/496456528

https://crbug.com/497047552

https://crbug.com/497769116

https://crbug.com/498746519

https://crbug.com/498809718

https://crbug.com/499023054

https://crbug.com/499119490

https://crbug.com/500018484

https://crbug.com/500034684

https://crbug.com/500104917

https://crbug.com/500387779

https://crbug.com/500767595

https://crbug.com/500880819

https://crbug.com/501722605

https://crbug.com/502206907

https://crbug.com/502248774

https://crbug.com/502449857

https://crbug.com/503889643

https://crbug.com/504586599

https://crbug.com/493957495

https://crbug.com/497896137

https://crbug.com/498285711

Plugin Details

Severity: Critical

ID: 310864

File Name: macosx_google_chrome_147_0_7727_137.nasl

Version: 1.2

Type: Local

Agent: macosx

Published: 4/29/2026

Updated: 4/30/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-7363

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-7343

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 4/28/2026

Vulnerability Publication Date: 4/28/2026

Reference Information

CVE: CVE-2026-7333, CVE-2026-7334, CVE-2026-7335, CVE-2026-7336, CVE-2026-7337, CVE-2026-7338, CVE-2026-7339, CVE-2026-7340, CVE-2026-7341, CVE-2026-7342, CVE-2026-7343, CVE-2026-7344, CVE-2026-7345, CVE-2026-7346, CVE-2026-7347, CVE-2026-7348, CVE-2026-7349, CVE-2026-7350, CVE-2026-7351, CVE-2026-7352, CVE-2026-7353, CVE-2026-7354, CVE-2026-7355, CVE-2026-7356, CVE-2026-7357, CVE-2026-7358, CVE-2026-7359, CVE-2026-7360, CVE-2026-7361, CVE-2026-7363