Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19170

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in Google Chrome's WebGL component. A remote attacker could exploit a use-after-free vulnerability by enticing a user to visit a specially crafted HTML page. This could potentially allow the attacker to perform a sandbox escape, breaking out of the browser's security protections and gaining further access to the system.

Отчет

Important: A use-after-free vulnerability in the WebGL component of Chromium could lead to a sandbox escape. This flaw allows a remote attacker to execute arbitrary code outside the browser's security sandbox by enticing a user to visit a specially crafted HTML page. While requiring user interaction, the ability to bypass browser security protections makes this an Important concern for Red Hat users of Chromium.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512321chromium-browser: Google Chrome: Sandbox escape via use after free in WebGL

EPSS

Процентиль: 24%
0.00317
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
5 дней назад

CVE-2026-19170 Use after free in WebGL

CVSS3: 9.6
debian
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...

CVSS3: 9.6
github
10 дней назад

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

EPSS

Процентиль: 24%
0.00317
Низкий

8.8 High

CVSS3