Use After Free Vulnerability in Google Chrome's Skia Component
CVE-2026-19176

7.5HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-19176?

A vulnerability in the Skia component of Google Chrome exists that allows a remote attacker to exploit a use after free condition. This can occur in the renderer process, enabling the attacker to execute arbitrary code. By delivering a specially crafted HTML page, the attacker can compromise users' security, making it essential for Chrome users to update their browsers to the latest versions to mitigate potential risks.

Affected Version(s)

Chrome 151.0.7922.109

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.