Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76036

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in Dawn in Google Chrome on Android. This buffer overflow vulnerability allows a remote attacker to execute arbitrary code outside of the sandbox. This can be achieved by enticing a user to visit a specially crafted HTML page.

Отчет

This Important flaw in Dawn, as used in Chromium-based browsers, allows a remote attacker to execute arbitrary code outside the browser's sandbox. This occurs when a user visits a specially crafted HTML page, leading to a buffer overflow. The impact is significant due to the potential for arbitrary code execution, even though user interaction is required.

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2518267chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page

EPSS

Процентиль: 55%
0.0081
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 1 месяца назад

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
около 1 месяца назад

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
debian
около 1 месяца назад

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0. ...

CVSS3: 9.6
github
около 1 месяца назад

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

suse-cvrf
28 дней назад

Security update for chromium

EPSS

Процентиль: 55%
0.0081
Низкий

8.3 High

CVSS3