Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19150

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in V8, the JavaScript engine used in Google Chrome. An inappropriate implementation vulnerability allowed a remote attacker to execute arbitrary code within the browser's sandbox. This could be achieved by enticing a user to visit a specially crafted HTML page. The primary impact is arbitrary code execution, which could lead to further system compromise.

Отчет

This vulnerability is rated as Important. An inappropriate implementation flaw in the V8 JavaScript engine, as used in the Chromium browser, allows a remote attacker to execute arbitrary code within the browser's sandbox. This can occur if a user is enticed to visit a specially crafted HTML page, potentially leading to further system compromise.

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2512363chromium-browser: Google Chrome (V8): Arbitrary code execution via crafted HTML page

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 дней назад

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19150 Inappropriate implementation in V8

CVSS3: 8.8
debian
10 дней назад

Inappropriate implementation in V8 in Google Chrome prior to 151.0.792 ...

CVSS3: 8.8
github
10 дней назад

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3