Skip to main content

Threats Tagged 'cve-2026-19173'

View all threats tagged with 'cve-2026-19173'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-19173

Threats Tagged 'cve-2026-19173'

Click on any threat for detailed analysis and mitigation recommendations

0

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154) * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173) * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161) * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176) * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984) * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804) * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713) * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787) * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783) * webkitgtk: use-after-free of JSCValue function parameters (CVE-2026-78376) * chromium-browser: Skia: Information disclosure via out-of-bounds read in crafted media file (CVE-2026-79020) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43795) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-64715) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64718) * webkitgtk: Visiting a maliciously crafted website may leak sensitive data (CVE-2026-64778) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64779) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64780) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64782) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64784) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65331) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65332) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65334) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65335) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65336) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65337) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65338) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65340) * webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2026-65341) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65351) * webkitgtk: Validate the full FeatureList array once in OpenTypeVerticalData findFeature (CVE-2026-83596) * chromium-browser: skia: chromium-browser: Information leak in Skia (CVE-2026-84359) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-84635) * webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2026-64753) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

This security update for Chromium addresses multiple critical vulnerabilities including numerous use-after-free issues, out-of-bounds writes, heap buffer overflows, race conditions, integer overflows, and insufficient validation of untrusted input. These vulnerabilities affect various components such as WebGL, Aura, Skia, V8, GPU, Views, and others. The update fixes these issues in Chromium version 151.0.7922.108. The vulnerabilities are critical due to their potential to cause memory corruption and other severe impacts.

Join the discussion
0

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Join the discussion
0

CVE-2026-19173 is a high-severity out-of-bounds write vulnerability in the Skia component of Google Chrome prior to version 151.0.7922.109. This flaw could allow a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox by using a crafted HTML page. The vulnerability affects desktop versions of Chrome and has a CVSS score of 8.3, indicating a significant risk if exploited. There is no explicit vendor advisory stating the patch status, but the vulnerability is fixed in Chrome version 151.0.7922.109.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-19173
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses