Description
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Chrome versions before 151.0.7922.109, a use‑after‑free flaw in the Views component allows a remote attacker who can coax a user into performing specific UI gestures to trigger heap corruption when loading a crafted HTML page. The flaw is classified as CWE‑416 and carries a Chromium severity rating of High, indicating that the corrupted heap could potentially be leveraged to execute arbitrary code or disrupt the browser process.

Affected Systems

Google Chrome browsers running any revision earlier than 151.0.7922.109 are impacted. No additional vendors or products are listed as affected.

Risk and Exploitability

The vulnerability requires a user to visit a malicious web page and perform certain UI gestures, so it is a user‑interaction‑dependent remote exploitation vector. No EPSS score is available, and the issue is not in the CISA KEV catalog. Because the flaw can corrupt heap objects it may lead to remote code execution if an attacker can craft the appropriate input sequence. Given its high severity and the lack of an availability countermeasure, enterprises should treat it as a high‑risk exploit in the pipeline.

Generated by OpenCVE AI on August 6, 2026 at 23:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 151.0.7922.109 or later (the official update that fixes the flaw).
  • Enable Chrome auto‑update so that future security releases are applied automatically without manual intervention.
  • Use enterprise policy to restrict sites that can trigger gesture‑based interactions, reducing the window for the attack vector.

Generated by OpenCVE AI on August 6, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Views Allows Potential Heap Corruption via Crafted Web Page

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:50.894Z

Reserved: 2026-08-06T16:51:49.881Z

Link: CVE-2026-19159

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:00:05Z

Weaknesses