Description
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Skia graphics library used by Google Chrome. An attacker who can compromise a renderer process can use a specially crafted HTML document to execute arbitrary code inside the sandbox, which can lead to full system compromise. The weakness is identified as CWE‑416.

Affected Systems

Google Chrome versions earlier than 151.0.7922.109 are affected. The flaw applies to all platforms that load compromised renderer processes through normal browsing of malicious content.

Risk and Exploitability

The CVE is rated high severity and is not currently listed in the CISA KEV catalog. The EPSS score is not available, so exact exploitation probability is unknown. The exploit requires the attacker to first compromise the renderer process, which is typically achieved with a malicious web page delivered over the network. Once the renderer is subverted, the use‑after‑free can be triggered to execute code within the renderer’s sandbox, potentially breaking out if additional sandbox escapes exist.

Generated by OpenCVE AI on August 7, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 151.0.7922.109 or later, which includes the Skia patch.
  • Enable Chrome Site Isolation (force site isolation policy) to limit the impact of a renderer compromise.
  • Implement OS‑level sandbox tightening by ensuring Chrome runs with minimal privileges and disabling unnecessary extensions.

Generated by OpenCVE AI on August 7, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-06T20:33:56.628Z

Reserved: 2026-08-06T16:51:54.416Z

Link: CVE-2026-19176

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:30:06Z

Weaknesses