Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19166

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.3

Описание

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Web Authentication in Google Chrome. A remote attacker could exploit a use-after-free vulnerability by enticing a user to visit a specially crafted HTML page. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise.

Отчет

This is an Important vulnerability in Chromium's Web Authentication component that could allow a remote attacker to escape the browser's sandbox. Exploitation requires user interaction, such as visiting a specially crafted HTML page, but could lead to significant system compromise beyond the browser's confines.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512229chromium-browser: Google Chrome: Sandbox escape due to use-after-free in Web Authentication

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
10 дней назад

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19166 Use after free in Web Authentication

CVSS3: 9.6
debian
10 дней назад

Use after free in Web Authentication in Google Chrome prior to 151.0.7 ...

CVSS3: 9.6
github
10 дней назад

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 High

CVSS3