Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19153

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.7

Описание

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. Insufficient validation of untrusted input in the Workers component could allow a remote attacker, who has already compromised the renderer process, to bypass site isolation. This could enable the attacker to access sensitive information or further compromise the user's system.

Отчет

Important: This flaw in Chromium-based browsers allows a remote attacker to bypass site isolation. Exploitation requires a compromised renderer process and a specially crafted HTML page, enabling the attacker to circumvent a critical security boundary designed to protect user data.

Дополнительная информация

Статус:

Important
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2512308chromium-browser: Google Chrome: Site isolation bypass via insufficient input validation in Workers

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
10 дней назад

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.1
nvd
10 дней назад

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19153 Insufficient validation of untrusted input in Workers

CVSS3: 8.1
debian
10 дней назад

Insufficient validation of untrusted input in Workers in Google Chrome ...

CVSS3: 8.1
github
10 дней назад

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

8.7 High

CVSS3