
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19176 is a use-after-free vulnerability in the Skia graphics library within Google Chrome, classified as High severity. It affects Google Chrome versions prior to 151.0.7922.109 on Windows and Mac, and prior to 151.0.7922.108 on Linux. The vulnerability was reported by researcher WinD39 - Huynh Dinh Vu on 2026-07-29 and publicly disclosed on 2026-08-06 as part of a broader Chrome stable channel update addressing 41 security fixes. It carries a CVSS v3.1 base score of 7.5 (High) (Chrome Advisory, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Skia graphics rendering library. Exploitation requires that an attacker has already compromised the Chrome renderer process; once that precondition is met, the attacker can trigger the use-after-free condition via a crafted HTML page to execute arbitrary code within the sandbox. The attack vector is network-based, requires user interaction (e.g., visiting a malicious page), and has high attack complexity due to the prerequisite of renderer compromise. The Chromium issue tracker reference is #540157141, though bug details remain restricted pending broad user update (Chrome Advisory, GitHub Advisory).
Successful exploitation allows a remote attacker who has already compromised the Chrome renderer process to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. The impact spans high confidentiality, integrity, and availability — an attacker could read sensitive browser data, modify rendered content, or cause application crashes. While execution is constrained to the sandbox, this vulnerability could serve as a stepping stone in a multi-stage exploit chain targeting a full sandbox escape (GitHub Advisory, Chrome Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the high attack complexity and the prerequisite of prior renderer compromise. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Nessus detection plugins 333159 and 333160 are available for identifying vulnerable Chrome installations (Feedly).
Google has released a patch in Chrome stable channel version 151.0.7922.108 for Linux and 151.0.7922.108/.109 for Windows and Mac. Users and administrators should update Chrome to version 151.0.7922.109 (Windows/Mac) or 151.0.7922.108 (Linux) or later immediately. Enabling automatic updates in Chrome ensures timely receipt of security patches. No configuration-based workarounds have been published; upgrading is the only recommended remediation (Chrome Advisory).
The CIS (Center for Internet Security) published an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19176, could allow for arbitrary code execution. The broader Chrome 151.0.7922.108 update, which addressed 41 security issues including several Critical-rated use-after-free bugs, received attention from the security community via VulDB and AUSCERT bulletins. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-19176 has been observed beyond standard vulnerability tracking (CIS Advisory, AUSCERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."