Sceawere

Vulnerability Detail

CVE-2026-19159UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Views Use-After-Free Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Use after free
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-06T22:16:58.230Z",
  "pubdate": "2026-08-06T22:16:58.230Z",
  "executiveSummary": "A use-after-free vulnerability exists within the Views component of Google Chrome prior to version 151.0.7922.109, presenting a high-severity security risk to end users.\nThe flaw enables a remote threat actor to potentially achieve heap corruption and execute arbitrary actions within the context of the application by leveraging a specifically crafted HTML page.\nSuccessful exploitation of this vulnerability requires user interaction, specifically convincing a user to engage in targeted UI gestures while visiting a malicious webpage.\nThe affected product is Google Chrome, specifically versions prior to 151.0.7922.109, impacting the stability and integrity of the browser heap.\nRisk implications include potential memory corruption and subsequent application instability or unpredictable behavior, driven by a remote attacker over the network via web content.\nAttacker capabilities are constrained by the need for social engineering and user engagement, requiring specific UI interactions to trigger the vulnerable code path within the browser rendering and UI management pipeline.",
  "technicalDetails": "The root cause of the vulnerability stems from a use-after-free condition located in the Views component of the Chromium browser architecture.\nA use-after-free condition occurs when memory is dynamically allocated, released, and subsequently referenced again, leading to undefined behavior and potential memory corruption.\nThe vulnerable component is responsible for managing UI elements and graphical views within Google Chrome.\nThe affected software versions include all Google Chrome releases prior to 151.0.7922.109.\nExploitation requires no prior authentication or local privileges, but network exposure is present as the attack vector relies on web content served via a crafted HTML page.\nThe attack flow begins when a remote attacker hosts a malicious, crafted HTML page designed to interact with the Views component of the browser.\nThe attacker must successfully convince a user to navigate to the malicious page and engage in specific UI gestures, which trigger the erroneous handling of memory allocations within the Views framework.\nUpon execution of the required UI gestures, the browser accesses a pointer that references memory which has already been freed.\nThis dangling pointer dereference allows the crafted HTML page to manipulate heap structures, resulting in heap corruption.\nThe post-exploitation impact includes application crashes, potential disruption of browser services, and memory corruption that may be leveraged for further malicious execution depending on heap layout manipulation."
}
CVE-2026-19159: Google Chrome Views Use-After-Free Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere