
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19558 is a use-after-free vulnerability in the Extensions component of Google Chrome that allows an attacker who convinces a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. It affects all versions of Google Chrome prior to 151.0.7922.137. The vulnerability was reported by researcher @bean5oup on July 20, 2026, and Google disclosed and patched it on August 11, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Extensions subsystem. A use-after-free condition arises when the Extensions component references memory that has already been freed, potentially allowing an attacker to corrupt heap memory and redirect code execution. Exploitation requires user interaction — specifically, convincing the target to install a crafted malicious Chrome Extension — after which the extension can trigger the memory misuse to achieve code execution within the browser's sandbox. The Chromium issue tracker entry is referenced as issue #536676756 (Chrome Release, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code within the Chrome browser's sandbox environment, with high impact to confidentiality, integrity, and availability of the browser process. While the sandbox limits direct access to the underlying operating system, code execution within the sandbox can serve as a stepping stone for sandbox escape chains or data exfiltration from the browser context (e.g., cookies, saved credentials, browsing history). The attack is network-delivered but requires user interaction to install the malicious extension, limiting mass exploitation but still posing significant risk to targeted users (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the requirement for user interaction. The EPSS score is approximately 0.18–0.25%, placing it in a low-to-moderate exploitation probability range. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Chrome Release).
chrome://crashes page.%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows or ~/.config/google-chrome/Default/Extensions/ on Linux) that are not recognized by the user.Google has released Chrome version 151.0.7922.137 (Linux) and 151.0.7922.137/.138 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism (Chrome Release). As an interim workaround, organizations should disable or remove untrusted or unrecognized extensions and implement enterprise extension management policies (e.g., via ExtensionInstallAllowlist or ExtensionInstallBlocklist group policies) to restrict which extensions can be installed. Users should only install extensions from verified publishers on the Chrome Web Store and review existing installed extensions for legitimacy.
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-19558, could allow for arbitrary code execution, recommending immediate patching. Security news outlets including CyberSecurityNews, GBHackers, and Cryptika covered the Chrome 151 release, highlighting the five high-severity use-after-free flaws patched in this update. Red Hat tracked the issue via Bugzilla and assessed it as high severity for Chromium-based packages on Linux. The broader security community noted the vulnerability was part of a batch of five use-after-free fixes in a single Chrome stable release, reflecting ongoing memory safety challenges in the browser (Chrome Release, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."