CVE-2026-19152

Description

A flaw was found in Chromium. Insufficient policy enforcement within the Navigation component allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape. This vulnerability can be exploited via a specially crafted HTML page, leading to a bypass of security boundaries.

Statement

This Important vulnerability in Chromium's Navigation component allows a remote attacker to perform a sandbox escape. Exploitation requires a prior compromise of the renderer process, typically through a crafted HTML page, enabling the attacker to bypass security boundaries and potentially gain further system access.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.