Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19177

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Chromium. A remote attacker, after compromising the renderer process, could exploit insufficient validation of untrusted input in the user interface (UI) by crafting a malicious HTML page. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise.

Отчет

This is an Important vulnerability in Chromium that allows a remote attacker to perform a sandbox escape. While exploitation requires a prior compromise of the renderer process and user interaction with a specially crafted HTML page, a successful attack could lead to significant impact on the system's confidentiality, integrity, and availability. The high attack complexity and user interaction prevent this flaw from being rated Critical.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2512352chromium-browser: Chromium: Sandbox escape via crafted HTML page

EPSS

Процентиль: 29%
0.00357
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
10 дней назад

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
10 дней назад

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
5 дней назад

CVE-2026-19177 Insufficient validation of untrusted input in UI

CVSS3: 8.3
debian
10 дней назад

Insufficient validation of untrusted input in UI in Google Chrome prio ...

CVSS3: 8.3
github
10 дней назад

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 29%
0.00357
Низкий

8 High

CVSS3