Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19159

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium-browser. This use-after-free vulnerability in the Views component allows a remote attacker to potentially exploit heap corruption. By convincing a user to engage in specific user interface gestures and visit a crafted HTML page, an attacker could achieve arbitrary code execution.

Отчет

This Important flaw in chromium-browser allows a remote attacker to achieve arbitrary code execution. The vulnerability, a use-after-free in the Views component, requires a user to visit a specially crafted HTML page and engage in specific user interface gestures, making it dependent on user interaction but still posing a significant risk due to the potential for full system compromise.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512324chromium-browser: Chromium: Arbitrary code execution via use-after-free in Views

EPSS

Процентиль: 26%
0.00335
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 7.5
nvd
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19159 Use after free in Views

CVSS3: 7.5
debian
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...

CVSS3: 7.5
github
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 26%
0.00335
Низкий

7.5 High

CVSS3