CVE-2026-19175
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-19175 is a use-after-free vulnerability in the Payments component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.109. The vulnerability was reported internally by Google on 2026-07-29 and publicly disclosed on 2026-08-06 as part of a stable channel update. It carries a Chromium security severity rating of High, though a formal CVSS score has not yet been published (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Payments component. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires a victim to visit a specially crafted HTML page, after which the attacker could leverage the memory corruption to escape Chrome's sandbox and execute code in a less-restricted context. The Chromium issue tracker entry is issue #540138836, though full technical details remain restricted pending broad user patching (Chrome Release, GitHub Advisory).

Impact

Successful exploitation could allow a remote, unauthenticated attacker to escape Chrome's sandbox and execute arbitrary code outside the restricted browser process environment. This could lead to full compromise of the underlying host system, enabling data theft, installation of malware, or further lateral movement within a network. The impact is particularly significant because no user interaction beyond visiting a malicious webpage is required beyond the initial page load (Chrome Release, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 151.0.7922.109 on Windows, Mac, or Linux.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers the use-after-free condition in Chrome's Payments component, manipulating memory allocation and deallocation sequences to control freed memory.
  3. Deliver payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website.
  4. Trigger vulnerability: When the victim loads the page in a vulnerable Chrome version, the use-after-free condition is triggered in the Payments component, corrupting heap memory.
  5. Sandbox escape: Leverage the memory corruption to redirect execution flow and escape Chrome's sandbox, gaining code execution privileges in the context of the browser process or beyond.
  6. Post-exploitation: With sandbox escape achieved, deploy additional payloads (e.g., malware, remote access tools) or access sensitive system resources (Chrome Release).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome browser process to unknown external IP addresses or domains following a webpage visit; unusual DNS queries originating from the browser process.
  • Process: Unexpected child processes spawned by the Chrome renderer or browser process (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.
  • Logs: System or application logs showing Chrome process crashes or abnormal termination followed by suspicious process creation events; Windows Event Logs showing new process creation (Event ID 4688) with Chrome as the parent.
  • File System: Unexpected files written to disk by the Chrome process, particularly executables or scripts in user-writable directories (e.g., %TEMP%, %APPDATA%).

Mitigation and workarounds

Google has released a patch in Chrome version 151.0.7922.109 (Windows/Mac) and 151.0.7922.108 (Linux), which addresses this vulnerability along with 40 other security fixes. Users should update Chrome immediately by navigating to Settings > Help > About Google Chrome and applying any available updates. Enabling automatic updates is strongly recommended to ensure timely receipt of future security patches. As a temporary workaround prior to patching, users should avoid visiting untrusted or unknown websites (Chrome Release).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19175, could allow for arbitrary code execution, recommending immediate patching (CIS Advisory). AusCERT also published a bulletin (ESB-2026.9205) alerting its constituency to the Chrome stable channel update. Community discussion on platforms such as Infosec.Exchange and VulDB noted the vulnerability shortly after disclosure, though no significant independent researcher commentary or detailed technical analysis has been published as of the disclosure date.

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19175CRITICAL9.6
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026
CVE-2026-19174HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesAug 06, 2026
CVE-2026-19177HIGH8.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026
CVE-2026-19173HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesAug 06, 2026
CVE-2026-19176HIGH7.5
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management