Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76040

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium-browser. This use-after-free vulnerability allows a remote attacker, through social engineering, to execute arbitrary code outside of the sandbox by enticing a user to visit a specially crafted HTML page. This could lead to a complete compromise of the affected system.

Отчет

This Important use-after-free vulnerability in chromium-browser allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires social engineering to entice a user to visit a specially crafted HTML page, making user interaction a prerequisite for a successful attack.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2518272chromium-browser: chromium-browser: Arbitrary code execution via use-after-free vulnerability

EPSS

Процентиль: 42%
0.00508
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
около 1 месяца назад

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76040 Use after free in Browser

CVSS3: 8.8
debian
около 1 месяца назад

Use after free in Browser in Google Chrome on on Mac prior to 151.0.79 ...

CVSS3: 8.8
github
около 1 месяца назад

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 42%
0.00508
Низкий

8.3 High

CVSS3

Уязвимость CVE-2026-76040