Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19151

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium-browser. A remote attacker could exploit a use-after-free vulnerability in the V8 JavaScript engine by crafting a malicious HTML page. This could allow the attacker to execute arbitrary code within the browser's sandbox, potentially leading to further system compromise.

Отчет

Important: This use-after-free flaw in the V8 JavaScript engine of chromium-browser allows a remote attacker to execute arbitrary code by enticing a user to visit a specially crafted HTML page. While execution is initially contained within the browser's sandbox, the potential for further system compromise elevates the risk to Important, as it bypasses typical browser security mechanisms.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512336chromium-browser: Chromium-browser: Arbitrary code execution via use-after-free in V8

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 дней назад

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19151 Use after free in V8

CVSS3: 8.8
debian
10 дней назад

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed ...

CVSS3: 8.8
github
10 дней назад

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3