CVE-2026-7351: Race in MHTML
Chromium: CVE-2026-7351 Race in MHTML
Other sources
Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome/Chromium-based Microsoft Edge (ingests Chromium)to a version that resolves this vulnerability.Fixed in 147.0.7727.138 - Compensating control
Prevent users from installing untrusted/malicious Chrome/Edge extensions (attacker tricked user into installing a malicious extension to trigger the MHTML race and leak cross-origin data).
- Operational
If any malicious extension may have been installed, remove it and review/rotate any secrets or tokens that could have been exposed via cross-origin data leakage.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-7351?
CVE-2026-7351 has a high severity rating due to the potential for data leakage from cross-origin sources.
How do I fix CVE-2026-7351?
To fix CVE-2026-7351, users should update Google Chrome to version 147.0.7727.138 or later.
What versions of Google Chrome are affected by CVE-2026-7351?
CVE-2026-7351 affects Google Chrome versions prior to 147.0.7727.138.
Can CVE-2026-7351 affect Microsoft Edge?
Yes, CVE-2026-7351 can potentially affect Microsoft Edge if the browser is based on an affected version of Chromium.
What kind of attacks are possible with CVE-2026-7351?
CVE-2026-7351 allows attackers to leak cross-origin data via a crafted Chrome Extension.