Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19152

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2

Описание

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Chromium. Insufficient policy enforcement within the Navigation component allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape. This vulnerability can be exploited via a specially crafted HTML page, leading to a bypass of security boundaries.

Отчет

This Important vulnerability in Chromium's Navigation component allows a remote attacker to perform a sandbox escape. Exploitation requires a prior compromise of the renderer process, typically through a crafted HTML page, enabling the attacker to bypass security boundaries and potentially gain further system access.

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2512349chromium-browser: Chromium: Sandbox escape via insufficient policy enforcement in Navigation

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19152 Inappropriate implementation in Navigation

CVSS3: 8.3
debian
10 дней назад

Insufficient policy enforcement in Navigation in Google Chrome prior t ...

CVSS3: 8.3
github
10 дней назад

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.2 High

CVSS3