CVE-2026-19557: Use After Free
Chromium: CVE-2026-19557 Use after free in TabStrip
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.86 - Upgrade
Upgrade
Microsoft Edge (Chromium-based) / Chromium (Mac)to a version that resolves this vulnerability.Fixed in 151.0.7922.137 - Upgrade
Upgrade
Google Chrome (Mac)to a version that resolves this vulnerability.Fixed in 151.0.7922.137 - Compensating control
On affected systems, reduce risk from renderer compromise by limiting access to untrusted websites/pages (e.g., use site isolation and restrict browsing to trusted content) until Chrome/Edge are updated to 151.0.7922.137 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19557?
The severity of CVE-2026-19557 is classified as High.
How do I fix CVE-2026-19557?
To fix CVE-2026-19557, users should update Google Chrome to version 151.0.7922.137 or later.
What vulnerability does CVE-2026-19557 exploit?
CVE-2026-19557 exploits a use after free vulnerability in the TabStrip component of Google Chrome.
What could an attacker achieve by exploiting CVE-2026-19557?
An attacker could potentially perform a sandbox escape by leveraging this vulnerability via a crafted HTML page.
On which platform is CVE-2026-19557 found?
CVE-2026-19557 is found in Google Chrome on Mac operating systems prior to version 151.0.7922.137.