CVE-2026-19557: Use After Free
Published Aug 11, 2026
·Updated
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<151.0.7922.137
Event History
Aug 11, 2026
CVE Published
via MITRE·09:23 PM
Data Sourced
via MITRE·09:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19557?
The severity of CVE-2026-19557 is classified as High.
2
How do I fix CVE-2026-19557?
To fix CVE-2026-19557, users should update Google Chrome to version 151.0.7922.137 or later.
3
What vulnerability does CVE-2026-19557 exploit?
CVE-2026-19557 exploits a use after free vulnerability in the TabStrip component of Google Chrome.
4
What could an attacker achieve by exploiting CVE-2026-19557?
An attacker could potentially perform a sandbox escape by leveraging this vulnerability via a crafted HTML page.
5
On which platform is CVE-2026-19557 found?
CVE-2026-19557 is found in Google Chrome on Mac operating systems prior to version 151.0.7922.137.