Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16807

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the Codecs component of Google Chrome. A remote attacker could exploit an out-of-bounds write vulnerability through a specially crafted HTML page. This could potentially allow the attacker to bypass security restrictions and gain unauthorized access to the underlying system.

Отчет

This flaw is rated as Important because a remote attacker could exploit an out-of-bounds write vulnerability in the Codecs component of Google Chrome, or applications embedding Chromium-based web engines, via a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing the attacker to bypass security restrictions and gain unauthorized access to the underlying system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2506636chromium-browser: Google Chrome Codecs: Sandbox escape via crafted HTML page

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
18 дней назад

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
18 дней назад

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
17 дней назад

Chromium: CVE-2026-16807 Out of bounds write in Codecs

CVSS3: 8.8
debian
18 дней назад

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 ...

CVSS3: 8.8
github
18 дней назад

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3