Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19138

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.3

Описание

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's CrashReporting component. A heap buffer overflow vulnerability allows a remote attacker, who has already compromised the renderer process, to potentially escape the browser's security sandbox by crafting a malicious HTML page. This could lead to further compromise of the user's system.

Отчет

This Important vulnerability in Chromium's CrashReporting component allows a remote attacker to perform a sandbox escape. After an initial compromise of the renderer process, typically through user interaction with a crafted HTML page, a heap buffer overflow can be exploited to bypass the browser's security sandbox. This is considered Important due to the potential for further system compromise once the sandbox is breached, despite the prerequisite of an already compromised renderer.

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2512318chromium-browser: Google Chrome: Sandbox escape via heap buffer overflow in CrashReporting

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19138 Heap buffer overflow in CrashReporting

CVSS3: 8.3
debian
10 дней назад

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0 ...

CVSS3: 8.3
github
10 дней назад

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 High

CVSS3