CVE-2026-19173

Google · Chrome

An out of bounds write vulnerability exists in the Skia graphics library within Google Chrome, potentially allowing for memory corruption.

Executive summary

An out of bounds write vulnerability in the Google Chrome Skia library poses a significant risk of memory corruption and potential arbitrary code execution.

Vulnerability

The flaw is categorized as an out of bounds write (CWE-787) within the Skia library. It is an unauthenticated, remote vulnerability that requires user interaction, typically through visiting a malicious web page, to trigger.

Business impact

With a CVSS score of 8.3, this vulnerability represents a high risk to organizational security. Successful exploitation could lead to application crashes or the execution of arbitrary code, which may result in full system compromise for the affected user if the browser is running with sufficient privileges.

Remediation

Immediate Action: Apply the latest security updates provided by Google to patch the vulnerable Skia component.

Proactive Monitoring: Monitor endpoint detection and response logs for indicators of memory-based attacks or unexpected browser process terminations.

Compensating Controls: Utilize browser isolation technologies or endpoint protection platforms that can detect and block memory corruption attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Memory corruption vulnerabilities in core graphics libraries like Skia are high-value targets for attackers. It is essential to ensure all workstations and servers running Google Chrome are updated immediately to prevent potential exploitation.