CVE-2026-19159

7.5

Google · Chrome

A use after free vulnerability in Google Chrome Views allows remote attackers to trigger heap corruption via a crafted HTML page and specific user UI gestures.

Executive summary

A high-severity use after free vulnerability in Google Chrome could allow a remote attacker to achieve heap corruption and potentially execute arbitrary code on a victim system.

Vulnerability

This flaw is a use after free vulnerability (CWE-416) within the Views component of Google Chrome. It requires an unauthenticated remote attacker to trick a user into performing specific UI gestures while visiting a malicious HTML page to trigger the memory corruption.

Business impact

The potential for heap corruption poses a significant security risk, as it may lead to arbitrary code execution or a complete browser crash. Given the CVSS score of 7.5, the vulnerability is classified as high, indicating that successful exploitation could lead to unauthorized system access, data theft, or compromise of user sessions.

Remediation

Immediate Action: Update all installations of Google Chrome to version 151.0.7922.109 or later immediately to resolve the memory management flaw.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process behavior that may indicate an attempt to trigger heap corruption.

Compensating Controls: Ensure that browser security settings are strictly enforced via centralized management policies to limit the execution of untrusted scripts or the interaction with suspicious websites.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a clear risk to browser security and should be treated as a priority for patch management. Organizations should deploy the updated version of Google Chrome across their entire fleet to ensure users are protected against this memory corruption risk.

More Google CVEs

Sources