
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19559 is a use-after-free vulnerability in the HTML component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.137 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-07-28 and publicly disclosed on 2026-08-11 alongside the Chrome 151 stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's HTML processing subsystem. A use-after-free flaw arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the contents of that memory region and redirect execution flow. Exploitation requires an attacker to craft a malicious HTML page that triggers the improper memory access when rendered by a vulnerable Chrome instance. The bug was tracked internally as Chromium issue 540100588, and access to full technical details remains restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code within the Chrome sandbox by tricking a user into visiting a malicious webpage. While the sandbox limits the immediate blast radius, sandbox escape chained with this vulnerability could lead to full system compromise, data exfiltration, or installation of malware. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for significant data exposure and system disruption (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported internally by Google, suggesting it was discovered through internal security research rather than external threat actor activity. The EPSS score is approximately 0.31–0.40%, placing it in the 34th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
cmd.exe, powershell.exe, bash, curl, wget); Chrome renderer processes consuming abnormally high memory or crashing repeatedly.Google has released Chrome version 151.0.7922.137 (Linux) and 151.0.7922.137/.138 (Windows/Mac) which addresses this vulnerability. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. Enterprise administrators should push the update via policy management tools. No configuration-based workaround is available; patching is the only effective remediation. Microsoft Edge (Chromium-based) users should also monitor for a corresponding Edge update (Chrome Releases, Microsoft MSRC).
The Chrome 151 update, which patches five high-severity use-after-free vulnerabilities including CVE-2026-19559, received coverage from multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the batch of use-after-free fixes across V8, TabStrip, Extensions, HTML, and Blink components. The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome could allow for arbitrary code execution. The security community broadly recommended prompt patching given the High severity rating and the nature of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."