Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19557

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the TabStrip component of Chromium. A remote attacker, who has already compromised the renderer process, could exploit a use-after-free vulnerability by crafting a malicious HTML page. This could potentially allow the attacker to escape the browser's sandbox, leading to further system compromise.

Отчет

A use-after-free flaw in the TabStrip component of Chromium-based browsers could allow a remote attacker to escape the browser's sandbox. After an initial compromise of the renderer process, a crafted HTML page could lead to further system compromise. This vulnerability presents a significant security risk for users of affected Red Hat systems.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2514408chromium-browser: Chromium: Sandbox escape via use-after-free in TabStrip

EPSS

Процентиль: 19%
0.00266
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
4 дня назад

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
5 дней назад

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
2 дня назад

Chromium: CVE-2026-19557 Use after free in TabStrip

CVSS3: 8.3
debian
5 дней назад

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922 ...

CVSS3: 8.3
github
5 дней назад

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 19%
0.00266
Низкий

8.2 High

CVSS3