CVE-2026-19177

Description

A flaw was found in Chromium. A remote attacker, after compromising the renderer process, could exploit insufficient validation of untrusted input in the user interface (UI) by crafting a malicious HTML page. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise.

Statement

This is an Important vulnerability in Chromium that allows a remote attacker to perform a sandbox escape. While exploitation requires a prior compromise of the renderer process and user interaction with a specially crafted HTML page, a successful attack could lead to significant impact on the system's confidentiality, integrity, and availability. The high attack complexity and user interaction prevent this flaw from being rated Critical.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.