Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76045

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in WebGL in Google Chrome. This use-after-free vulnerability allows a remote attacker to execute arbitrary code within the browser's sandbox. This can be achieved by enticing a user to visit a specially crafted HTML page, leading to a high-severity security risk.

Отчет

This vulnerability is rated Important as it allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The use-after-free flaw in WebGL affects the Chromium browser, which is available in Red Hat Community Projects. Successful exploitation could lead to significant impact on confidentiality, integrity, and availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2518276chromium-browser: Google Chrome WebGL: Arbitrary code execution via use-after-free

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
около 1 месяца назад

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76045 Use after free in WebGL

CVSS3: 8.8
debian
около 1 месяца назад

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allow ...

CVSS3: 8.8
github
около 1 месяца назад

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3