Description
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Extensions component of Google Chrome prior to version 151.0.7922.137. An attacker who convinces a user to install a malicious extension can trigger the flaw and execute arbitrary code within the browser sandbox, leveraging the CWE‑416 weakness. This allows compromise of confidentiality, integrity, or availability if the sandbox is bypassed or the extension accesses privileged APIs.

Affected Systems

The affected product is the Google Chrome desktop browser on Windows, macOS and Linux. Every installation running a version earlier than 151.0.7922.137 is vulnerable; the fix is delivered through Chrome’s regular update channel.

Risk and Exploitability

The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a low exploitation probability at present, and the issue is not listed in the CISA KEV catalogue. The attack typically involves social engineering to persuade the user to install a malicious extension via phishing or deceptive web content. Once installed, the use‑after‑free can be triggered to run arbitrary code within the browser sandbox, potentially leading to privilege escalation if the sandbox is compromised.

Generated by OpenCVE AI on August 13, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update that includes the fix (v151.0.7922.137 or newer).
  • Remove any installed extensions that are not trusted or were installed without explicit user consent, especially those that request elevated permissions.
  • Disable automatic installation of extensions from untrusted sources by configuring enterprise policies or using security software to block anomalous extension installs.

Generated by OpenCVE AI on August 13, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4739-1 chromium security update
Debian DSA Debian DSA DSA-6436-1 chromium security update
History

Mon, 17 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 12 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Google Chrome Extensions: Arbitrary code execution via malicious extension installation
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-13T03:55:34.686Z

Reserved: 2026-08-11T17:27:19.349Z

Link: CVE-2026-19558

cve-icon Vulnrichment

Updated: 2026-08-12T13:38:19.086Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T22:17:21.440

Modified: 2026-08-17T12:40:17.680

Link: CVE-2026-19558

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T21:23:53Z

Links: CVE-2026-19558 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:15:02Z

Weaknesses