CVE-2026-19156: Buffer Overflow
Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Base)to a version that resolves this vulnerability.Fixed in 151.0.7922.109
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19156?
CVE-2026-19156 has a high severity rating due to the potential for heap corruption and exploitation through malicious Chrome extensions.
How do I fix CVE-2026-19156?
To fix CVE-2026-19156, update Google Chrome to version 151.0.7922.109 or later.
What impact does CVE-2026-19156 have on users?
CVE-2026-19156 can lead to heap buffer overflow vulnerabilities, potentially allowing attackers to execute arbitrary code on affected systems.
Who is affected by CVE-2026-19156?
Users with versions of Google Chrome prior to 151.0.7922.109 are vulnerable to CVE-2026-19156.
How can I determine if my version of Google Chrome is affected by CVE-2026-19156?
You can check your version of Google Chrome by going to the 'About' section in the menu to see if it's below 151.0.7922.109.