CVE-2026-19173
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-19173 is an out-of-bounds write vulnerability in the Skia graphics library within Google Chrome, classified as High severity by Chromium's security team. It affects Google Chrome versions prior to 151.0.7922.109 on Windows and Mac, and prior to 151.0.7922.108 on Linux. The vulnerability was reported by Vu Van Tien (@n0_Be3r) on July 24, 2026, and publicly disclosed on August 6, 2026, as part of a stable channel update addressing 41 security fixes (Chrome Releases). A formal CVSS score has not yet been published; the EPSS score is currently 0.0 (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), occurring in Chrome's Skia 2D graphics rendering library. An attacker who has already compromised the renderer process can trigger the out-of-bounds write via a specially crafted HTML page, potentially allowing memory corruption beyond the intended buffer boundaries. Exploitation requires a pre-compromised renderer process as a precondition, making this a second-stage or chained exploit typically used to escape Chrome's sandbox. The Chromium issue tracker reference is #538332338 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker with a compromised renderer process to escape Chrome's sandbox and potentially execute arbitrary code at the OS level, outside the browser's isolation boundary. This could lead to full system compromise, enabling unauthorized access to sensitive data, installation of malware, or lateral movement within a network. The impact is primarily on confidentiality and integrity, with availability also at risk if the attacker deploys destructive payloads (Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. Exploitation requires a pre-existing renderer process compromise, meaning this vulnerability is most likely to be used as part of a chained exploit rather than as a standalone attack. The CVE has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.

Exploitation steps

  1. Initial Renderer Compromise: Exploit a separate renderer-level vulnerability (e.g., a V8 JavaScript engine bug or another browser flaw) to gain code execution within Chrome's sandboxed renderer process.
  2. Craft Malicious HTML Page: Prepare a specially crafted HTML page that triggers the out-of-bounds write in Skia's graphics rendering code, likely through specific canvas, SVG, or CSS rendering operations that cause Skia to write data beyond an intended buffer boundary.
  3. Trigger OOB Write: Deliver the crafted HTML page to the victim's browser (e.g., via a malicious website, phishing link, or man-in-the-middle injection), causing the Skia library to perform the out-of-bounds memory write.
  4. Corrupt Sandbox Structures: Leverage the memory corruption to overwrite security-sensitive data structures or function pointers within the renderer process that control sandbox enforcement.
  5. Sandbox Escape: Use the corrupted memory state to redirect execution flow outside the sandboxed renderer, achieving code execution in a higher-privilege process context on the host OS (Chrome Releases).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 151.0.7922.109 for Windows and Mac, and 151.0.7922.108 for Linux. Users and administrators should update Chrome to the latest stable version immediately via the browser's built-in update mechanism or through enterprise deployment tools. As a supplementary measure, organizations can restrict access to untrusted or unknown websites and consider enabling additional process isolation features where available (Chrome Releases).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19173, could allow for arbitrary code execution, recommending prompt patching. AUSCERT also published a bulletin (ESB-2026.9205) referencing the Chrome stable channel update. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-19173 has been identified beyond standard vulnerability tracking coverage.

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19175CRITICAL9.6
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026
CVE-2026-19174HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesAug 06, 2026
CVE-2026-19177HIGH8.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026
CVE-2026-19173HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesAug 06, 2026
CVE-2026-19176HIGH7.5
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management