Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19172

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in Chromium's Views component. A remote attacker, after compromising the renderer process, could exploit a use-after-free vulnerability by crafting a malicious HTML page. This could potentially lead to a sandbox escape, allowing the attacker to execute code outside the confined environment.

Отчет

This vulnerability is rated Important as it allows a remote attacker to escape the Chromium sandbox after successfully compromising the renderer process. Exploiting a use-after-free flaw in the Views component with a crafted HTML page could bypass a critical security boundary, potentially leading to further system compromise beyond the browser's sandboxed environment.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512311chromium-browser: Chromium: Sandbox escape via use after free in Views

EPSS

Процентиль: 21%
0.00287
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
nvd
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

msrc
5 дней назад

CVE-2026-19172 Use after free in Views

CVSS3: 8.3
debian
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...

CVSS3: 8.3
github
10 дней назад

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

EPSS

Процентиль: 21%
0.00287
Низкий

8.2 High

CVSS3