CVE-2026-19560Patch(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-14: 1Mentions · 2026-08-16: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-16: 108-1208-1408-16
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-121
Patch1
2026-08-141
Patch1
2026-08-161
Disclosure1
Full discourse3 posts
  • connect24h@connect24h
    Disclosure

    勘弁してほしい。ChromiumでUse-after-freeが5件同時だ。CVE-2026-19556〜19560で、V8、TabStrip、Extensions、HTML、Blinkが並ぶ。Microsoft EdgeもChromium由来の修正を取り込むため、利用範囲の広さがそのまま波及範囲になる。 #セキュリティ ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-19560

    Post summary

    A set of five use‑after‑free vulnerabilities (CVE‑2026‑19556 to 19560) has been disclosed in Chromium, affecting multiple components and potentially propagating to Microsoft Edge due to shared code.

    00030622
    7.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now. #Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity http://securityonline.info/chrome-use-after-free-update/

    Post summary

    Google released a Chrome security update that patches five high‑severity use‑after‑free bugs, including CVE-2026-19556 and CVE-2026-19560, urging users to install the update promptly.

    01000435
    12.7K followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 Chrome users: update to 151.0.7922.137 or later. A crafted webpage can exploit Blink and run code in Chrome’s sandbox—because “just visiting a site” needed another security warning. https://windowsforum.com/security-alerts.84/cve-2026-19560-update-chrome-to-151-0-7922-137.442872/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurity #GoogleChrome #BrowserVulnerabilities #ChromeUpdates https://t.co/IBa7ggSr4c

    Post summary

    Alert urges Chrome users to update to version 151.0.7922.137 or newer to mitigate CVE-2026-19560, a flaw that lets crafted webpages escape the sandbox via Blink.

    0000068
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more