Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19175

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's Payments component. A remote attacker could exploit a use-after-free vulnerability by enticing a user to visit a specially crafted HTML page. This could potentially allow the attacker to escape the browser's security sandbox, gaining unauthorized access to the underlying system.

Отчет

This Important vulnerability in the Chromium browser's Payments component allows a remote attacker to escape the browser's sandbox by enticing a user to visit a specially crafted HTML page. This flaw could lead to further compromise of the user's system beyond the browser's security boundaries.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2512366chromium-browser: Google Chrome: Remote sandbox escape via use-after-free in Payments

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19175 Use after free in Payments

CVSS3: 9.6
debian
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...

CVSS3: 9.6
github
10 дней назад

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 22%
0.00295
Низкий

8.8 High

CVSS3