Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19155

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Chromium. This use-after-free vulnerability in the Payments component could allow a remote attacker, who has already compromised the renderer process, to potentially escape the browser's security sandbox. This could be achieved by enticing a user to visit a specially crafted HTML page.

Отчет

This Important flaw in Chromium's Payments component allows a remote attacker to potentially escape the browser's sandbox after compromising the renderer process. This elevated impact stems from the ability to bypass security boundaries, which could lead to further system compromise, even though it requires a prior successful exploit of the renderer.

Меры по смягчению последствий

To reduce the risk of exploitation, users should avoid visiting untrusted or suspicious websites. Additionally, employing browser sandboxing mechanisms can help contain potential compromises.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512345chromium-browser: Chromium: Sandbox escape via use-after-free in Payments

EPSS

Процентиль: 19%
0.00267
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19155 Use after free in Payments

CVSS3: 8.3
debian
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...

CVSS3: 8.3
github
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

9 Critical

CVSS3