CVE-2026-19147
Google · Chrome
A use after free vulnerability in the Aura component of Google Chrome on Linux allows for potential arbitrary code execution.
Executive summary
A high-severity use after free vulnerability in Google Chrome on Linux could allow a remote attacker to execute arbitrary code on the victim system.
Vulnerability
This is a use after free vulnerability affecting the Aura windowing system in Google Chrome on Linux. The vulnerability is triggered by an unauthenticated remote attacker through user interaction, such as visiting a compromised website.
Business impact
Successful exploitation can lead to arbitrary code execution within the context of the browser, potentially allowing attackers to escape the browser sandbox or gain persistence on the underlying Linux host. The CVSS score of 8.3 reflects the high risk to desktop environments running Linux, where browser-based attacks can lead to significant data loss or system compromise.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.109 or later using the distribution package manager or the official vendor update mechanism.
Proactive Monitoring: Review system logs for unusual browser process activity or unexpected crashes that may indicate an attempt to exploit memory corruption vulnerabilities.
Compensating Controls: Implement strict browser security policies and ensure that the browser is running with the least privilege necessary, which can limit the impact of a successful sandbox escape.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Linux-based endpoints are critical components of enterprise infrastructure. Security teams should prioritize patching Google Chrome on all Linux workstations and servers to address this high-severity vulnerability and maintain a secure operating environment.