CVE-2026-19158
7.5Google · Chrome
A use after free vulnerability in the Views component of Google Chrome on Windows allows a remote attacker to achieve heap corruption via a crafted HTML page and specific user UI gestures.
Executive summary
A use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code or corrupt memory by enticing a user to interact with a malicious webpage.
Vulnerability
This is a use after free vulnerability (CWE-416) within the Views component. An unauthenticated remote attacker can exploit this by convincing a user to perform specific UI gestures while visiting a crafted HTML page, leading to heap corruption.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk to organizational assets. Successful exploitation allows an attacker to compromise the integrity, confidentiality, and availability of the host system, potentially leading to unauthorized code execution or complete system compromise for the affected user.
Remediation
Immediate Action: Update all Google Chrome installations to version 151.0.7922.109 or later immediately to incorporate the vendor provided security patches.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity, specifically focusing on instances where the application crashes or exhibits unexpected behavior following navigation to untrusted web content.
Compensating Controls: Deploy endpoint protection platforms that can detect memory corruption patterns and utilize browser security policies to restrict the execution of untrusted scripts or the loading of potentially malicious external resources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for heap corruption and remote code execution, organizations should prioritize the deployment of the Chrome update across all Windows workstations. Failure to patch allows for a significant attack vector against end users, and administrators should ensure that automatic updates are enabled or enforced via management software to maintain a secure browser environment.