Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19144

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. This vulnerability, known as a use-after-free, occurs when the program attempts to use memory that has already been deallocated. A remote attacker could exploit this by tricking a user into visiting a specially crafted HTML page. Successful exploitation could lead to heap corruption, potentially allowing the attacker to execute arbitrary code.

Отчет

This Important flaw in Chromium allows a remote attacker to execute arbitrary code by tricking a user into visiting a malicious HTML page. The use-after-free vulnerability in the HTML component can lead to heap corruption, making it a significant risk for users of Red Hat-supported systems running Chromium, particularly when browsing untrusted web content.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512251chromium-browser: Google Chrome: Arbitrary code execution via crafted HTML page

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 дней назад

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19144 Use after free in HTML

CVSS3: 8.8
debian
10 дней назад

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowe ...

CVSS3: 8.8
github
10 дней назад

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3