AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19165

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Google Chrome extensions prior to version 151.0.7922.109 allows attackers to execute arbitrary code within a sandbox by tricking users into installing malicious extensions. This poses a significant risk to users, particularly those who frequently install third-party extensions. Organizations and individuals using affected versions of Chrome should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-19165
Severity
HIGH
CVSS
7.5
EPSS
0.23%
Chrome

Original NVD Description

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)