Description
Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow in the Base component of Google Chrome up to version 151.0.7922.109 allows an attacker who convinces a user to install a malicious extension to corrupt the heap. The detected weakness is a classic heap overflow (CWE-122). If successfully exploited, this could lead to arbitrary code execution or a denial‑of‑service condition in the compromised browser process.

Affected Systems

Google Chrome browsers on desktop platforms that have not yet been updated to version 151.0.7922.109. The vulnerability applies to the base component included in the stable channel builds delivered through Chrome updates.

Risk and Exploitability

The vulnerability carries a high severity rating in Chromium’s internal security score. Although an EPSS score is not available, the attack vector is clearly client‑side and relies on users installing a malicious extension, which is a low‑barrier scenario for social engineering. The knowledge that exploitable heap corruption can be triggered via extension code makes this a significant risk, though it is not listed in CISA’s KEV catalog. Vendors have not yet released a patch; therefore, the flaw remains available to potential attackers.

Generated by OpenCVE AI on August 6, 2026 at 23:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.109 or later, which contains the base component fix
  • Audit the list of installed extensions and remove any that are untrusted or appear suspicious
  • Implement enterprise Chrome policy to block installation of non‑whitelisted extensions

Generated by OpenCVE AI on August 6, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Chrome Base Enables Malicious Extension Exploitation

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:49.988Z

Reserved: 2026-08-06T16:51:49.049Z

Link: CVE-2026-19156

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow