Sceawere

Vulnerability Detail

CVE-2026-19164UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Codecs Sandbox Escape

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Insufficient validation of untrusted input
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-08-06T22:16:58.803Z",
  "pubdate": "2026-08-06T22:16:58.803Z",
  "executiveSummary": "This vulnerability is classified as an insufficient input validation flaw residing within the Codecs component of Google Chrome prior to version 151.0.7922.109.\nSuccessful exploitation of this security defect allows a remote adversary to achieve a sandbox escape, enabling arbitrary code execution or system interaction outside the constrained browser sandbox environment.\nThe affected product is Google Chrome, specifically versions preceding the patched release.\nThe risk implications are severe due to the potential compromise of the underlying operating system security boundaries.\nThe attacker capabilities require the victim to interact with a maliciously crafted HTML page, typically delivered via web browsing vectors.\nExploitation requirements include the remote delivery of a specially crafted payload designed to trigger the input validation failure within the affected media codec parsing routines.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate sanitization and verification of untrusted input processed by the Codecs component within Google Chrome.\nThe vulnerable component is explicitly identified as the Codecs subsystem, which handles complex media stream parsing and decoding operations.\nThe affected versions include all Google Chrome installations prior to 151.0.7922.109.\nAuthentication requirements are nonexistent, as the attack can be mounted remotely against unauthenticated users visiting a hostile web resource.\nPrivilege requirements are minimal from the attacker perspective; however, successful execution breaches the low-privilege renderer sandbox.\nNetwork exposure is inherent to web-based attack vectors, requiring the target to process network-delivered content via the browser.\nThe exploitation method involves a remote attacker constructing a malicious HTML page embedded with specially crafted media payloads designed to exploit the parsing logic flaws in the Codecs subsystem.\nThe step-by-step attack flow begins when a victim navigates to the attacker-controlled webpage using a vulnerable version of Google Chrome.\nThe browser parses the embedded malicious media content, routing the untrusted input directly into the vulnerable Codecs parsing routines without sufficient validation checks.\nDue to the absence of rigorous bounds and data integrity checks, memory corruption or logical state errors occur within the parsing engine.\nThe attacker leverages this anomalous state to manipulate control flow or execute arbitrary instructions, ultimately breaking out of the restricted Chromium sandbox isolation mechanism.\nThe post-exploitation impact includes the potential execution of unauthorized code with the privileges of the user process, compromising host integrity beyond the browser boundary."
}
CVE-2026-19164: Google Chrome Codecs Sandbox Escape (CRITICAL Severity, CVSS: 9.6) - Sceawere