August 2026 Patch TuesdayMSRC-2026-08-browser-release-notesNormal patch window

Microsoft · MSRC-2026-08-browser-release-notes

Linked CVE review

Deploy Microsoft Browser update for Microsoft Edge (Chromium-based)

Linked CVEs
39
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
9.6
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
39 of 39 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-19176 Scheduled assessment
Google Chrome - Use After Free

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.51% · 41.3th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-19145 Scheduled assessment
Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.5th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19150 Scheduled assessment
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.5th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19151 Scheduled assessment
Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.6th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19162 Scheduled assessment
Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.5th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19168 Scheduled assessment
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.5th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19174 Scheduled assessment
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.5th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19166 Critical technical severity
Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.39% · 31.3th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19157 Critical technical severity
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.38% · 30.3th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-19149 Critical technical severity
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19164 Critical technical severity
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19170 Critical technical severity
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19171 Critical technical severity
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19175 Critical technical severity
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19144 Scheduled assessment
Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19169 Scheduled assessment
Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

8.8 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.34% · 26.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19153 Scheduled assessment
Google Chrome - Improper Input Validation

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

8.1 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.33% · 24.0th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19138 Scheduled assessment
Google Chrome - Heap-based Buffer Overflow

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.33% · 23.9th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19173 Scheduled assessment
Google Chrome - Out-of-bounds Write

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.32% · 23.4th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-19177 Scheduled assessment
Google Chrome - Improper Input Validation

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.32% · 23.4th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19137 Scheduled assessment
Google Chrome - Use After Free

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19140 Scheduled assessment
Google Chrome - Use After Free

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19147 Scheduled assessment
Google Chrome - Use After Free

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19148 Scheduled assessment
Google Chrome - Out-of-bounds Write

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19152 Scheduled assessment
Google Chrome - Protection Mechanism Failure

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19155 Scheduled assessment
Google Chrome - Use After Free

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19163 Scheduled assessment
Google Chrome - Use After Free

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19172 Scheduled assessment
Google Chrome - Use After Free

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

8.3 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19142 Scheduled assessment
Google Chrome - Use After Free

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19158 Scheduled assessment
Google Chrome - Use After Free

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19159 Scheduled assessment
Google Chrome - Use After Free

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.30% · 21.2th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19165 Scheduled assessment
Google Chrome - Use After Free

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.27% · 17.0th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19156 Scheduled assessment
Google Chrome - Heap-based Buffer Overflow

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.25% · 15.0th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19139 Scheduled assessment
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

7.4 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.09% · 0.4th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-70339 Scheduled assessment
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

5.4 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.41% · 33.6th percentileForecast date: 2026-10-08NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Mitigation available. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19160 Scheduled assessment
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

3.1 · CVSS 3.1 · LowSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.40% · 32.1th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-19161 Scheduled assessment
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

3.1 · CVSS 3.1 · LowSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.32% · 23.0th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-19146 Scheduled assessment
Google Chrome - Use of Uninitialized Variable

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

5.3 · CVSS 3.1 · MediumSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.31% · 21.7th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-19167 Scheduled assessment
Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

3.1 · CVSS 3.1 · LowSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.23% · 12.7th percentileForecast date: 2026-10-08NETWORK · HIGH complexity · NONE privileges · REQUIRED user interactionScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.