Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19149

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.3

Описание

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in the Aura component of Google Chrome. A remote attacker could exploit a use-after-free vulnerability by crafting a malicious HTML page. This could allow the attacker to bypass security restrictions (sandbox escape) and execute unauthorized code on the affected system, posing a critical risk to data and system integrity.

Отчет

An Important vulnerability exists in the Aura component of Chromium, as distributed in Fedora and EPEL. This flaw allows a remote attacker to achieve a sandbox escape by enticing a user to process a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox, significantly compromising system integrity and confidentiality.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512246chromium-browser: Google Chrome: Sandbox escape via use-after-free vulnerability in Aura

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
5 дней назад

CVE-2026-19149 Use after free in Aura

CVSS3: 9.6
debian
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...

CVSS3: 9.6
github
10 дней назад

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

8.3 High

CVSS3