Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19142

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. A remote attacker could exploit a use-after-free vulnerability in the Views component by convincing a user to interact with specific user interface elements through a specially crafted HTML page. This could lead to heap corruption, potentially allowing the attacker to execute arbitrary code on the affected system.

Отчет

This Important vulnerability in Chromium's Views component allows a remote attacker to achieve code execution. Exploitation requires a user to interact with a specially crafted HTML page, which could lead to heap corruption. This risk is elevated due to the potential for arbitrary code execution within the browser's context.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512220chromium-browser: Google Chrome: Remote code execution via use after free in Views

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 7.5
nvd
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19142 Use after free in Views

CVSS3: 7.5
debian
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...

CVSS3: 7.5
github
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3