Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19158

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. A use-after-free vulnerability in the Views component could allow a remote attacker to exploit heap corruption. This can occur if a user is convinced to engage in specific user interface (UI) gestures while visiting a specially crafted HTML page, potentially leading to arbitrary code execution.

Отчет

This Important flaw in Chromium's Views component allows arbitrary code execution. A remote attacker could exploit heap corruption by convincing a user to visit a specially crafted HTML page and perform specific UI gestures. This user interaction requirement slightly reduces the immediate risk, but successful exploitation could lead to a complete compromise of the affected system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512262chromium-browser: Google Chrome: Arbitrary code execution via use-after-free in Views

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 7.5
nvd
10 дней назад

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19158 Use after free in Views

CVSS3: 7.5
debian
10 дней назад

Use after free in Views in Google Chrome on Windows prior to 151.0.792 ...

CVSS3: 7.5
github
10 дней назад

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3