Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5874

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

A flaw was found in Google Chrome. A remote attacker could exploit a use-after-free vulnerability in the PrivateAI component by convincing a user to engage in specific user interface (UI) gestures through a crafted HTML page. This could potentially allow the attacker to bypass the browser's security sandbox, leading to unauthorized access or control over the system.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2456798Google Chrome: Chromium: Google Chrome: Sandbox escape via use-after-free in PrivateAI

EPSS

Процентиль: 21%
0.00068
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
6 дней назад

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
nvd
6 дней назад

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

msrc
4 дня назад

Chromium: CVE-2026-5874 Use after free in PrivateAI

CVSS3: 9.6
debian
6 дней назад

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 al ...

CVSS3: 9.6
github
6 дней назад

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

EPSS

Процентиль: 21%
0.00068
Низкий

9.6 Critical

CVSS3