Description
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Skia graphics library used by Google Chrome. An attacker who can compromise a renderer process can use a specially crafted HTML document to execute arbitrary code inside the sandbox. The weakness is identified as CWE‑416.

Affected Systems

Google Chrome versions earlier than 151.0.7922.109 are affected. The flaw applies to all platforms that load compromised renderer processes through normal browsing of malicious content.

Risk and Exploitability

The CVE is rated high severity, with a CVSS score of 7.5, and is not currently listed in the CISA KEV catalog. The EPSS score is not available, so exact exploitation probability is unknown. The exploit requires the attacker to first compromise the renderer process, which is typically achieved with a malicious web page delivered over the network. Once the renderer is subverted, the use‑after‑free can be triggered to execute code within the renderer’s sandbox.

Generated by OpenCVE AI on August 7, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 151.0.7922.109 or later, which includes the Skia patch.
  • Enable Chrome Site Isolation (force site isolation policy) to limit the impact of a renderer compromise.
  • Implement OS‑level sandbox tightening by ensuring Chrome runs with minimal privileges and disabling unnecessary extensions.

Generated by OpenCVE AI on August 7, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4728-1 chromium security update
Debian DSA Debian DSA DSA-6422-1 chromium security update
History

Fri, 07 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Skia Enables Remote Code Execution via Renderer Compromise

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-07T03:55:54.752Z

Reserved: 2026-08-06T16:51:54.416Z

Link: CVE-2026-19176

cve-icon Vulnrichment

Updated: 2026-08-07T00:33:20.634Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-06T22:17:00.150

Modified: 2026-08-07T15:24:54.257

Link: CVE-2026-19176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:00:04Z

Weaknesses