Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19137

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 9

Описание

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in Google Chrome on Android. This vulnerability, a use-after-free error in the WebGL component, could be exploited by a remote attacker. After compromising the renderer process, the attacker could craft a malicious HTML page to trigger the flaw. This could potentially lead to a sandbox escape, allowing the attacker to gain elevated privileges or further control over the system.

Отчет

This Important vulnerability in WebGL within Chromium allows a remote attacker, after compromising the renderer process, to perform a sandbox escape via a crafted HTML page. This flaw, while initially reported for Android, affects Chromium on Red Hat systems, enabling an attacker to gain further access beyond the browser's security boundaries. Exploitation requires user interaction with malicious web content.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512315chromium-browser: Google Chrome on Android: Sandbox escape via use after free in WebGL

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
nvd
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
5 дней назад

CVE-2026-19137 Use after free in WebGL

CVSS3: 8.3
debian
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...

CVSS3: 8.3
github
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

9 Critical

CVSS3