Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19140

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's GPU component. This use-after-free vulnerability allows a remote attacker, who has already compromised the browser's renderer process, to potentially escape the browser's security sandbox. This escape can be achieved by tricking a user into visiting a specially crafted HTML page.

Отчет

This Important flaw in the Google Chrome GPU component allows a remote attacker to perform a sandbox escape. Exploitation requires a prior compromise of the browser's renderer process and user interaction, such as visiting a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512212chromium-browser: Google Chrome GPU: Sandbox escape via use after free vulnerability in crafted HTML.

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19140 Use after free in GPU

CVSS3: 8.3
debian
10 дней назад

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed ...

CVSS3: 8.3
github
10 дней назад

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3