
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19174 is an integer overflow vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all Google Chrome versions prior to 151.0.7922.109 on Windows and Mac, and prior to 151.0.7922.108 on Linux. The vulnerability was reported by Seunghyun Lee (@0x10n) of QED Audit on July 24, 2026, and publicly disclosed on August 6, 2026, alongside a patch release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Advisory, GitHub Advisory).
The root cause is an integer overflow or wraparound (CWE-190, mapped to CAPEC-92: Forced Integer Overflow) in Chrome's V8 JavaScript engine. When V8 performs certain arithmetic calculations, the resulting value can exceed the maximum representable integer, wrapping around to a small or negative number, which can corrupt memory state and be leveraged for code execution. Exploitation requires no special privileges but does require user interaction — specifically, a victim must visit a malicious or attacker-controlled HTML page. The Chromium issue tracker entry (issue #538378084) is currently restricted pending broad patch rollout (Chrome Advisory, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, achieving high confidentiality, integrity, and availability impact on the affected browser process. While execution is constrained to the sandbox, this class of V8 vulnerability is frequently chained with a sandbox escape to achieve full system compromise. Affected assets include any desktop Chrome installation on Windows, Mac, or Linux running a version prior to the patched release (Chrome Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for user interaction. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog at this time (GitHub Advisory).
cmd.exe, powershell.exe, /bin/sh, curl, wget); Chrome renderer processes consuming abnormally high CPU or memory.Google has released a patch in Chrome 151.0.7922.109 for Windows and Mac, and 151.0.7922.108 for Linux. Users and administrators should update Chrome to the latest stable version immediately via the browser's built-in update mechanism or through enterprise deployment tools. As a temporary workaround where immediate patching is not feasible, organizations can restrict access to untrusted websites via web filtering, disable JavaScript execution for untrusted sources using browser policies, and conduct user awareness training to avoid clicking suspicious links (Chrome Advisory).
The vulnerability was part of a large Chrome stable channel update addressing 41 security fixes, which drew attention from the security community given the breadth of the release. The CIS Security advisory noted that multiple vulnerabilities in this update, including CVE-2026-19174, could allow for arbitrary code execution. No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard vulnerability tracking and advisory coverage (Chrome Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."