CVE-2026-19177
Description
A flaw was found in Chromium. A remote attacker, after compromising the renderer process, could exploit insufficient validation of untrusted input in the user interface (UI) by crafting a malicious HTML page. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise.
Statement
This is an Important vulnerability in Chromium that allows a remote attacker to perform a sandbox escape. While exploitation requires a prior compromise of the renderer process and user interaction with a specially crafted HTML page, a successful attack could lead to significant impact on the system's confidentiality, integrity, and availability. The high attack complexity and user interaction prevent this flaw from being rated Critical.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.