Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19173

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Skia, a 2D graphics library utilized within Chromium-based browsers. A remote attacker, having already compromised the browser's renderer process, could exploit an out-of-bounds write vulnerability. This exploitation occurs by enticing a user to visit a specially crafted HTML page. The successful execution of this attack could enable the attacker to escape the browser's security sandbox, potentially leading to further compromise of the underlying system.

Отчет

An Important out-of-bounds write vulnerability in Skia, as used in various Red Hat components, allows a compromised browser renderer process to escape its security sandbox. This flaw requires user interaction to process a specially crafted HTML page. Successful exploitation could lead to further compromise of the underlying system beyond the browser's confines.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2512277chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium

EPSS

Процентиль: 19%
0.00267
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19173 Out of bounds write in Skia

CVSS3: 8.3
debian
10 дней назад

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 a ...

CVSS3: 8.3
github
10 дней назад

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00267
Низкий

9 Critical

CVSS3