Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19147

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. A remote attacker, who has already compromised the browser's renderer process, could exploit a use-after-free vulnerability in the Aura component by tricking a user into visiting a specially crafted HTML page. This could potentially allow the attacker to perform a sandbox escape, bypassing security mechanisms and gaining further access to the system.

Отчет

This Important use-after-free vulnerability in the Aura component of Chromium allows a remote attacker to perform a sandbox escape. Exploitation requires a prior compromise of the browser's renderer process, which could then be leveraged via a crafted HTML page to bypass security boundaries. This poses a significant risk for Red Hat platforms such as Fedora and EPEL, as it could lead to further system compromise beyond the browser's sandbox.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512239chromium-browser: Google Chrome: Sandbox escape via use-after-free vulnerability in Aura

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19147 Use after free in Aura

CVSS3: 8.3
debian
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...

CVSS3: 8.3
github
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3