Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19558

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.3

Описание

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

A flaw was found in Google Chrome Extensions. This use-after-free vulnerability allows a remote attacker to execute arbitrary code within the browser's sandbox. Exploitation occurs when a user is convinced to install a specially crafted malicious extension.

Отчет

This Important flaw in Google Chrome Extensions allows for arbitrary code execution within the browser's sandbox. Exploitation requires a user to be convinced to install a malicious extension, limiting the attack vector to user interaction rather than remote, unauthenticated access.

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2514410chromium-browser: Google Chrome Extensions: Arbitrary code execution via malicious extension installation

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
nvd
5 дней назад

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

msrc
2 дня назад

Chromium: CVE-2026-19558 Use after free in Extensions

CVSS3: 7.5
debian
5 дней назад

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 ...

CVSS3: 7.5
github
5 дней назад

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

7.3 High

CVSS3