Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19148

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the GPU component of Google Chrome on Linux. A remote attacker, who has already compromised the renderer process, could exploit an out-of-bounds write vulnerability by tricking a user into visiting a specially crafted HTML page. This could potentially allow the attacker to escape the browser's sandbox, leading to further system compromise.

Отчет

This Important vulnerability in the Chromium GPU component allows a compromised renderer process to perform a sandbox escape. While requiring prior compromise of the renderer and user interaction with a crafted HTML page, successful exploitation could lead to further system compromise beyond the browser's sandbox, elevating the risk due to the potential for broader system impact.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512274chromium-browser: Google Chrome: Sandbox escape via out-of-bounds write in GPU

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19148 Out of bounds write in GPU

CVSS3: 8.3
debian
10 дней назад

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.79 ...

CVSS3: 8.3
github
10 дней назад

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-19148