Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19156

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

A flaw was found in Google Chrome's Base component. An attacker could convince a user to install a malicious extension, leading to a heap buffer overflow. This vulnerability allows for potential heap corruption, which could be exploited to impact the integrity and availability of the browser.

Отчет

An Important heap buffer overflow flaw was found in the Base component of Chromium. This vulnerability requires a user to install a specially crafted malicious extension, which could then lead to heap corruption and potentially compromise the browser's integrity and availability. While user interaction is required, the potential for significant impact on affected systems warrants the Important severity.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512310chromium-browser: Google Chrome: Heap buffer overflow allows heap corruption via malicious extension

EPSS

Процентиль: 13%
0.00225
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
nvd
10 дней назад

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19156 Heap buffer overflow in Base

CVSS3: 7.5
debian
10 дней назад

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 ...

CVSS3: 7.5
github
10 дней назад

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

EPSS

Процентиль: 13%
0.00225
Низкий

7.8 High

CVSS3