Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19157

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.4
EPSS Низкий

Описание

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in ANGLE, a component within Google Chrome on Android. This out-of-bounds write vulnerability allows a remote attacker to potentially perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This could lead to an attacker executing arbitrary code outside the browser's security sandbox.

Отчет

This Important flaw in the ANGLE component of Chromium allows a remote attacker to achieve a sandbox escape. Exploitation requires user interaction, where a victim must visit a specially crafted HTML page, enabling an attacker to execute arbitrary code outside the browser's security sandbox. This bypasses security boundaries, leading to potential compromise of the underlying system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 7webkitgtk4Affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512296chromium-browser: angle: ANGLE: Sandbox escape via out-of-bounds write in Google Chrome on Android

EPSS

Процентиль: 30%
0.00384
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
2 месяца назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
2 месяца назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
2 месяца назад

CVE-2026-19157 Out of bounds write in ANGLE

CVSS3: 9.6
debian
2 месяца назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151. ...

CVSS3: 9.6
github
2 месяца назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

EPSS

Процентиль: 30%
0.00384
Низкий

8.4 High

CVSS3