Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19164

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Codecs in Google Chrome. Insufficient validation of untrusted input in this component could allow a remote attacker to exploit the vulnerability. By crafting a malicious HTML page, an attacker could potentially perform a sandbox escape, leading to the execution of arbitrary code outside the browser's security sandbox.

Отчет

This Important vulnerability in Chromium's Codecs component allows a remote attacker to perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This bypasses the browser's security sandbox, potentially leading to arbitrary code execution outside of the isolated environment.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2512284chromium-browser: Google Chrome Codecs: Sandbox escape via crafted HTML page

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
10 дней назад

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19164 Insufficient validation of untrusted input in Codecs

CVSS3: 9.6
debian
10 дней назад

Insufficient validation of untrusted input in Codecs in Google Chrome ...

CVSS3: 9.6
github
10 дней назад

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3