chromereleases.googleblog.com
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html CVE-2026-19166
CRITICAL
Google Chrome Web Authentication Use-After-Free
Record summary
CVE-2026-19166 has a selected CVSS score of 9.6 (critical).
Description
Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | 151.0.7922.109 to < 151.0.7922.109 | affected |
References
3issues.chromium.org
https://issues.chromium.org/issues/536584251 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19166