Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19163

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the Media component of Google Chrome. This use-after-free vulnerability could allow a remote attacker, who has already compromised the renderer process, to potentially escape the browser's sandbox. This could be achieved by enticing a user to visit a specially crafted HTML page, leading to a higher level of system access.

Отчет

Important: A use-after-free vulnerability in the Media component of Chromium can lead to a sandbox escape. This flaw allows a remote attacker, who has already compromised the renderer process through a crafted HTML page, to bypass the browser's security sandbox and potentially execute arbitrary code on the system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512203chromium-browser: Google Chrome: Sandbox escape via use-after-free in Media component

EPSS

Процентиль: 19%
0.00267
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19163 Use after free in Media

CVSS3: 8.3
debian
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...

CVSS3: 8.3
github
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

8 High

CVSS3