Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79282

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

A flaw was found in ANGLE, a component of Google Chrome on Android. This 'use after free' vulnerability allows a remote attacker to execute arbitrary code outside the browser's security sandbox. This can be exploited by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to a complete compromise of the affected device.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6webkitgtkNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 7webkitgtk4Affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2524048chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page

EPSS

Процентиль: 40%
0.00483
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 2 месяцев назад

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
nvd
около 2 месяцев назад

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
debian
около 2 месяцев назад

Use after free in ANGLE in Google Chrome on on Android prior to 152.0. ...

CVSS3: 9.6
github
около 2 месяцев назад

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

rocky
19 дней назад

Important: webkit2gtk3 security update

EPSS

Процентиль: 40%
0.00483
Низкий

9.6 Critical

CVSS3