Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19174

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in V8, the JavaScript engine used in Google Chrome. This integer overflow vulnerability allows a remote attacker to execute arbitrary code within the browser's security sandbox—a protective environment that limits what a program can do. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized operations within the sandboxed environment.

Отчет

This is an Important vulnerability in the V8 JavaScript engine, utilized by Chromium-based browsers. An integer overflow allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The requirement for user interaction to trigger the flaw contributes to its Important severity, as direct network exploitation without user action is not possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2512348chromium-browser: Google Chrome V8: Arbitrary code execution via crafted HTML page

EPSS

Процентиль: 28%
0.00353
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 дней назад

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19174 Integer overflow in V8

CVSS3: 8.8
debian
10 дней назад

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...

CVSS3: 8.8
github
10 дней назад

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 28%
0.00353
Низкий

8.8 High

CVSS3