Description
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient validation of input data in Chrome’s Codecs component, which can be triggered via a crafted HTML page. This flaw permits a remote adversary to escape Chrome’s sandbox, potentially allowing execution of code outside the browser process or elevation of privileges on the host system. Chromium has classified the issue as high severity.

Affected Systems

All installations of Google Chrome built before version 151.0.7922.109 are affected. The product is Chrome, distributed by Google. Current releases as of the advisory include the fix, but systems that remain on older versions remain vulnerable.

Risk and Exploitability

The CVSS score is not listed, but the advisory labels the problem as high severity. No EPSS data is available, and the vulnerability is not presently tracked in the CISA KEV catalog. An attacker could exploit the weakness by serving the malicious HTML page from a website or embedding it in an email attachment, leveraging the browser’s renderer to trigger the sandbox escape. Successful exploitation would grant code execution outside the confinement of Chrome, potentially leading to full system compromise depending on user privileges.

Generated by OpenCVE AI on August 7, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest version (151.0.7922.109 or newer).
  • If an update cannot be applied immediately, disable or restrict the use of untrusted media codecs and local file executions in the browser settings.
  • Ensure that automatic updates are enabled so that future security patches are applied without manual intervention.

Generated by OpenCVE AI on August 7, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Chrome Codec Input Validation Leading to Sandbox Escape

Fri, 07 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:53.054Z

Reserved: 2026-08-06T16:51:51.226Z

Link: CVE-2026-19164

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation