
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19560 is a use-after-free vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all Google Chrome versions prior to 151.0.7922.137 across Windows, Mac, and Linux platforms. The vulnerability was reported by researcher WinD39 - Huynh Dinh Vu on July 30, 2026, and Google disclosed and patched it on August 11, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's Blink rendering engine. When processing a specially crafted HTML page, Blink can reference memory that has already been freed, potentially allowing an attacker to control execution flow and run arbitrary code. Exploitation requires user interaction — specifically, a victim must visit a malicious or attacker-controlled web page — but requires no privileges or authentication on the attacker's part. The Chromium issue tracker entry is tracked at https://issues.chromium.org/issues/540482895, though access may be restricted pending broad user patching (Chrome Releases, GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code within the Chrome sandbox on the victim's machine, with high impact to confidentiality, integrity, and availability. While the sandbox limits direct host OS access, this vulnerability could serve as a stepping stone in a sandbox escape chain when combined with additional exploits. Affected users across Windows, Mac, and Linux running Chrome prior to 151.0.7922.137 are at risk of data theft, browser session hijacking, or further compromise (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.31–0.40%, placing it in the 34th percentile for exploitation likelihood within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable due to the required user interaction (Feedly).
chrome.exe, chrome on Linux/Mac) spawning unexpected child processes or exhibiting anomalous behavior such as accessing files outside normal browser directories.Google has released Chrome version 151.0.7922.137 (Linux) and 151.0.7922.137/.138 (Windows/Mac) which addresses this vulnerability. Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings > Help > About Google Chrome) or through enterprise deployment tools. As a temporary workaround where immediate patching is not feasible, restrict user access to untrusted or unknown websites. Chromium-based browsers (e.g., Microsoft Edge) may also require updates from their respective vendors — Microsoft has published guidance via the MSRC (Chrome Releases, Microsoft MSRC).
The Chrome 151 update, which patches five high-severity use-after-free vulnerabilities including CVE-2026-19560, received coverage from multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, highlighting the batch of Blink, V8, and Extensions flaws addressed in the release. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Google Chrome could allow for arbitrary code execution. Red Hat and openSUSE also published security advisories and package updates for Chromium-based packages on their respective platforms (CIS Advisory, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."