Use After Free Vulnerability in Google Chrome Web Authentication
CVE-2026-19166

9.6CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-19166?

An issue identified in the Web Authentication component of Google Chrome prior to version 151.0.7922.109 involves a use after free condition. This vulnerability can be exploited by remote attackers to potentially execute a sandbox escape using a carefully crafted HTML page. Attackers could leverage this flaw to bypass Chrome's security measures, posing serious risks to user data and system integrity.

Affected Version(s)

Chrome 151.0.7922.109

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.