
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19557 is a use-after-free vulnerability in the TabStrip component of Google Chrome on macOS that allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. It was reported internally by Google on 2026-07-14 and publicly disclosed on August 11, 2026, as part of Chrome's stable channel update to version 151.0.7922.137. All Google Chrome versions prior to 151.0.7922.137 on Mac are affected. It carries a CVSS v3.1 base score of 8.3 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's TabStrip UI component on macOS. After memory associated with a tab strip object is freed, a dangling pointer can be dereferenced, allowing an attacker to control execution flow. Exploitation requires the attacker to have already compromised the renderer process (a prerequisite), and then deliver a crafted HTML page that triggers the use-after-free condition to escape the Chrome sandbox. The Chromium issue tracker references bug ID 534867485, though details remain restricted pending broad user update (Chrome Releases, GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker who has already gained a foothold in the Chrome renderer process to escape the browser sandbox, potentially achieving arbitrary code execution in the context of the host operating system on macOS. This sandbox escape breaks a critical security boundary, enabling access to system resources, sensitive user data, and potentially facilitating lateral movement or persistence beyond the browser. The scope change reflected in the CVSS score (S:C) underscores that the impact extends beyond the vulnerable component itself, affecting confidentiality, integrity, and availability at a high level (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Chrome Releases). The vulnerability was reported internally by Google, suggesting it may have been discovered through internal security research or fuzzing rather than external threat actor activity. The EPSS score is approximately 0.25–0.30%, placing it in the lower percentiles for near-term exploitation likelihood. Exploitation requires a chained attack — first compromising the renderer process, then triggering the TabStrip use-after-free — which increases attack complexity (AC:H) and limits opportunistic exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
bash, sh, python, curl) on macOS, particularly those not associated with normal browser helper processes.Google Chrome Helper) spawning network connections or file system writes outside expected browser data directories./tmp, or application support folders created by Chrome processes unexpectedly./var/log/system.log or Unified Log) showing abnormal process creation events originating from Chrome's browser process PID.~/Library/Application Support/Google/Chrome/ that may indicate memory corruption attempts.Google has released Chrome version 151.0.7922.137 (Linux) and 151.0.7922.137/.138 (Windows/Mac) which addresses this vulnerability. Users should update Google Chrome to version 151.0.7922.137 or later immediately, with priority given to macOS systems where this specific TabStrip vulnerability is exploitable. No configuration-based workaround is available; updating to the patched version is the only remediation. Enterprise administrators should use Google Admin Console or their endpoint management platform to push the update promptly across all managed macOS Chrome instances (Chrome Releases).
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19557, could allow for arbitrary code execution. Security news outlets including CyberSecurityNews, GBHackers, and SecurityOnline covered the Chrome 151 release, highlighting the five high-severity use-after-free flaws patched in this update. The vulnerability was also tracked by Kaspersky's threat intelligence portal and flagged in the Hawk-Eye weekly threat landscape digest for Week 33 of 2026. Community discussion on Reddit (r/Nable and r/msp) referenced the CVE in the context of N-able NCentral patch management follow-ups, indicating awareness among MSP communities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."