CVE-2026-19164
Description
A flaw was found in Codecs in Google Chrome. Insufficient validation of untrusted input in this component could allow a remote attacker to exploit the vulnerability. By crafting a malicious HTML page, an attacker could potentially perform a sandbox escape, leading to the execution of arbitrary code outside the browser's security sandbox.
Statement
This Important vulnerability in Chromium's Codecs component allows a remote attacker to perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This bypasses the browser's security sandbox, potentially leading to arbitrary code execution outside of the isolated environment.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.