AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19558

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Google Chrome extensions prior to version 151.0.7922.137 allows attackers to execute arbitrary code within a sandboxed environment by tricking users into installing malicious extensions. This poses a significant risk to users who may inadvertently install compromised extensions, potentially leading to unauthorized access or data breaches. Organizations and users utilizing affected versions of Chrome should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-19558
Severity
HIGH
CVSS
7.5
EPSS
0.23%
Chrome

Original NVD Description

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)