Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19171

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.3

Описание

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium-browser. This use-after-free vulnerability in the Media component allows a remote attacker to potentially escape the browser's security sandbox. Exploitation can occur by enticing a user to visit a specially crafted HTML page.

Отчет

An Important use-after-free vulnerability in the Chromium Media component can lead to a sandbox escape. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page, thereby bypassing the browser's security sandbox and potentially compromising the system further. This affects Chromium as distributed in Red Hat community projects.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512250chromium-browser: Chromium: Sandbox escape via use-after-free in Media component

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19171 Use after free in Media

CVSS3: 9.6
debian
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...

CVSS3: 9.6
github
10 дней назад

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 High

CVSS3