
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19173 is an out-of-bounds write vulnerability in the Skia graphics library within Google Chrome, classified as High severity by Chromium's security team. It affects Google Chrome versions prior to 151.0.7922.109 on Windows and Mac, and prior to 151.0.7922.108 on Linux. The vulnerability was reported by Vu Van Tien (@n0_Be3r) on July 24, 2026, and publicly disclosed on August 6, 2026, as part of a stable channel update addressing 41 security fixes (Chrome Releases). A formal CVSS score has not yet been published; the EPSS score is currently 0.0 (GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), occurring in Chrome's Skia 2D graphics rendering library. An attacker who has already compromised the renderer process can trigger the out-of-bounds write via a specially crafted HTML page, potentially allowing memory corruption beyond the intended buffer boundaries. Exploitation requires a pre-compromised renderer process as a precondition, making this a second-stage or chained exploit typically used to escape Chrome's sandbox. The Chromium issue tracker reference is #538332338 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker with a compromised renderer process to escape Chrome's sandbox and potentially execute arbitrary code at the OS level, outside the browser's isolation boundary. This could lead to full system compromise, enabling unauthorized access to sensitive data, installation of malware, or lateral movement within a network. The impact is primarily on confidentiality and integrity, with availability also at risk if the attacker deploys destructive payloads (Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. Exploitation requires a pre-existing renderer process compromise, meaning this vulnerability is most likely to be used as part of a chained exploit rather than as a standalone attack. The CVE has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
Google has released a patch in Chrome stable channel version 151.0.7922.109 for Windows and Mac, and 151.0.7922.108 for Linux. Users and administrators should update Chrome to the latest stable version immediately via the browser's built-in update mechanism or through enterprise deployment tools. As a supplementary measure, organizations can restrict access to untrusted or unknown websites and consider enabling additional process isolation features where available (Chrome Releases).
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19173, could allow for arbitrary code execution, recommending prompt patching. AUSCERT also published a bulletin (ESB-2026.9205) referencing the Chrome stable channel update. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-19173 has been identified beyond standard vulnerability tracking coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."