Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-19164: Google Chrome: Malicious HTML can escape security sandbox

CVE-2026-19164 CVE-2026-19164
Summary

A security issue in Google Chrome's Codecs feature allows hackers to create a malicious web page that could break out of the browser's security restrictions. This could potentially allow them to access and steal sensitive information on your computer. To stay safe, make sure your Google Chrome is updated to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
google chrome < 151.0.7922.109
Original title
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium se...
Original description
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Vulnerability type
CWE-20 Improper Input Validation
Published: 6 Aug 2026 · Updated: 7 Aug 2026 · First seen: 6 Aug 2026