CVE-2026-19171

9.6

Google · Chrome

A use after free vulnerability in the Media component of Google Chrome on Windows allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox, posing a severe risk to system integrity and data confidentiality.

Vulnerability

This vulnerability is a use after free flaw (CWE-416) within the Media component. An unauthenticated remote attacker can trigger this issue by enticing a user to visit a crafted HTML page, leading to a sandbox escape.

Business impact

The ability to escape the browser sandbox is a critical security failure, as it allows attackers to bypass the primary security boundary protecting the underlying operating system. With a CVSS score of 9.6, this flaw permits an attacker to execute arbitrary code with the privileges of the logged-in user, potentially leading to full system compromise, data exfiltration, and lateral movement within the network.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.109 or later immediately to incorporate the necessary memory management fixes.

Proactive Monitoring: Monitor endpoint security logs for signs of unusual browser behavior or unauthorized process creation spawned by the Chrome executable.

Compensating Controls: Ensure that users are operating with the principle of least privilege, which limits the potential damage an attacker can inflict if a sandbox escape is successful.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of sandbox escape vulnerabilities in widely used web browsers, organizations must prioritize the deployment of the update to Chrome version 151.0.7922.109. Failure to remediate this flaw exposes systems to severe risk from remote attackers using malicious web content. Expedited deployment across all managed workstations is strongly advised to maintain security posture.

More Google CVEs

Sources