What is CVE-2026-19558?
A Use after free vulnerability in Extensions in Google Chrome prior to version 151.0.7922.137 allowed an attacker to execute arbitrary code inside a sandbox via a malicious Chrome Extension. Users are advised to update their browser to the latest version.
Azərbaycanca: Google Chrome-un 151.0.7922.137 versiyasından əvvəlki versiyalarında Extensions komponentində aşkarlanan Use after free zəifliyi, zərərli bir uzantının quraşdırılması ilə sandbox daxilində ixtiyari kod icrasına imkan verir. İstifadəçilərə brauzerlərini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Google
FAQ2
In which component of Google Chrome was CVE-2026-19558 discovered?
This vulnerability is a Use after free vulnerability discovered in the Extensions component of Google Chrome.
What should users do to protect against CVE-2026-19558?
Users are advised to update their Google Chrome browser to version 151.0.7922.137 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.