CVE-2026-19164

Description

A flaw was found in Codecs in Google Chrome. Insufficient validation of untrusted input in this component could allow a remote attacker to exploit the vulnerability. By crafting a malicious HTML page, an attacker could potentially perform a sandbox escape, leading to the execution of arbitrary code outside the browser's security sandbox.

Statement

This Important vulnerability in Chromium's Codecs component allows a remote attacker to perform a sandbox escape by enticing a user to visit a specially crafted HTML page. This bypasses the browser's security sandbox, potentially leading to arbitrary code execution outside of the isolated environment.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.