Description
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free that occurs when Chrome's Media components on Windows release memory that can later be accessed again. A remote attacker delivering a crafted HTML page can trigger the memory reuse, which may allow the attacker to escape the browser sandbox and execute code with higher privileges. This flaw is identified as CWE‑416 and is considered high severity by Chromium.

Affected Systems

Google Chrome browsers running on Windows with versions earlier than 151.0.7922.109 are affected. All supported Windows platforms that ship these Chrome builds are at risk. The issue does not affect Chrome installations on other operating systems.

Risk and Exploitability

The CVSS assessment for this flaw is high, but no EPSS score is available, and it is not listed in the CISA KEV catalog, indicating no publicly known exploits so far. The likelihood of exploitation depends on the attacker’s ability to serve a malicious HTML page to a user. If the sandbox is enabled, the attacker’s capabilities are limited, but the possibility of breaking out into the host system still exists. The missing EPSS data means the exploitation probability is uncertain, and users should consider the high severity as a signal to take remediation seriously.

Generated by OpenCVE AI on August 6, 2026 at 23:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 151.0.7922.109 or later
  • Ensure Chromium sandboxing features remain enabled and have not been disabled by configuration or extensions
  • Block or restrict delivery of potentially malicious multimedia content from untrusted sources until the patch is applied

Generated by OpenCVE AI on August 6, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use after Free in Media Engine Enables Potential Sandbox Escape on Windows

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:54.828Z

Reserved: 2026-08-06T16:51:53.109Z

Link: CVE-2026-19171

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:00:05Z

Weaknesses