
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19175 is a use-after-free vulnerability in the Payments component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.109. The vulnerability was reported internally by Google on 2026-07-29 and publicly disclosed on 2026-08-06 as part of a stable channel update. It carries a Chromium security severity rating of High, though a formal CVSS score has not yet been published (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Payments component. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires a victim to visit a specially crafted HTML page, after which the attacker could leverage the memory corruption to escape Chrome's sandbox and execute code in a less-restricted context. The Chromium issue tracker entry is issue #540138836, though full technical details remain restricted pending broad user patching (Chrome Release, GitHub Advisory).
Successful exploitation could allow a remote, unauthenticated attacker to escape Chrome's sandbox and execute arbitrary code outside the restricted browser process environment. This could lead to full compromise of the underlying host system, enabling data theft, installation of malware, or further lateral movement within a network. The impact is particularly significant because no user interaction beyond visiting a malicious webpage is required beyond the initial page load (Chrome Release, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made.
cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.%TEMP%, %APPDATA%).Google has released a patch in Chrome version 151.0.7922.109 (Windows/Mac) and 151.0.7922.108 (Linux), which addresses this vulnerability along with 40 other security fixes. Users should update Chrome immediately by navigating to Settings > Help > About Google Chrome and applying any available updates. Enabling automatic updates is strongly recommended to ensure timely receipt of future security patches. As a temporary workaround prior to patching, users should avoid visiting untrusted or unknown websites (Chrome Release).
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19175, could allow for arbitrary code execution, recommending immediate patching (CIS Advisory). AusCERT also published a bulletin (ESB-2026.9205) alerting its constituency to the Chrome stable channel update. Community discussion on platforms such as Infosec.Exchange and VulDB noted the vulnerability shortly after disclosure, though no significant independent researcher commentary or detailed technical analysis has been published as of the disclosure date.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."