What is CVE-2026-19560?
A use after free vulnerability in Blink in Google Chrome prior to version 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Users should immediately update to the latest version of the browser.
Azərbaycanca: Google Chrome-un 151.0.7922.137 versiyasından əvvəlki versiyalarında Blink mühərrikində "use after free" zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücumçuya xüsusi hazırlanmış HTML səhifə vasitəsilə sandbox daxilində ixtiyari kod icra etməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal brauzerlərini ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Google
FAQ2
Which browser engine is affected by CVE-2026-19560?
This vulnerability affects the Blink engine in Google Chrome.
What can an attacker potentially achieve by exploiting CVE-2026-19560?
A remote attacker can execute arbitrary code inside a sandbox via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.