Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19157

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.4

Описание

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in ANGLE, a component within Google Chrome on Android. This out-of-bounds write vulnerability allows a remote attacker to potentially perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This could lead to an attacker executing arbitrary code outside the browser's security sandbox.

Отчет

This Important flaw in the ANGLE component of Chromium allows a remote attacker to achieve a sandbox escape. Exploitation requires user interaction, where a victim must visit a specially crafted HTML page, enabling an attacker to execute arbitrary code outside the browser's security sandbox. This bypasses security boundaries, leading to potential compromise of the underlying system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512296chromium-browser: ANGLE: Sandbox escape via out-of-bounds write in Google Chrome on Android

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
10 дней назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
5 дней назад

CVE-2026-19157 Out of bounds write in ANGLE

CVSS3: 9.6
debian
10 дней назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151. ...

CVSS3: 9.6
github
10 дней назад

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

8.4 High

CVSS3