Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19145

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the Translate component of Chromium. A remote attacker could exploit a use-after-free vulnerability by enticing a user to visit a specially crafted HTML page. This could lead to arbitrary code execution within the sandbox environment, potentially compromising the affected system.

Отчет

This Important flaw in the Chromium Translate component enables remote attackers to achieve arbitrary code execution within the browser's sandbox. The vulnerability is triggered by user interaction with a specially crafted HTML page, posing a significant risk due to the common exposure to untrusted web content.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512217chromium-browser: Chromium: Arbitrary code execution via use-after-free in Translate component

EPSS

Процентиль: 28%
0.00353
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 дней назад

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19145 Use after free in Translate

CVSS3: 8.8
debian
10 дней назад

Use after free in Translate in Google Chrome prior to 151.0.7922.109 a ...

CVSS3: 8.8
github
10 дней назад

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 28%
0.00353
Низкий

8.8 High

CVSS3