Description
Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use-after-free flaw in Chrome extensions allows an attacker who convinces a user to install a malicious extension to gain execution of arbitrary code within the browser’s sandbox. The problem arises when the browser frees an object and later accesses it, violating memory safety and granting the attacker a window to execute arbitrary payloads. The vulnerability is classified as CWE‑416 and is noted by Chromium as high severity.

Affected Systems

Google Chrome, versions prior to 151.0.7922.109, are susceptible. Clients using any older stable channel update that does not include the patch may be exposed.

Risk and Exploitability

The vulnerability’s impact is confined to the user who installs the malicious extension, but it can be leveraged for broader compromise if the extension acts as a foothold for further attacks. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires the user to install a malicious extension, the attack vector depends on social engineering. The high Chromium severity indicates that a successful exploit could lead to compromised confidentiality or integrity of user data and potentially the host system if the sandbox is bypassed.

Generated by OpenCVE AI on August 6, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable version 151.0.7922.109 or newer to apply the use‑after‑free fix
  • Uninstall any extensions that appear suspicious or that the user did not explicitly install
  • Configure Chrome’s extension management to block installation of unverified or developer‑mode extensions and enforce corporate policies if applicable

Generated by OpenCVE AI on August 6, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Extensions Allows Arbitrary Code Execution

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:53.537Z

Reserved: 2026-08-06T16:51:51.518Z

Link: CVE-2026-19165

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:15:04Z

Weaknesses