CVE-2026-6919General(google / android)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome
  • linux_kernel
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-21)
  • 10 total mentions across 7 days

Affected systems

Products
androidchromelinux_kernelwindows

1 version affected across 4 products

Deep dive

Activity timeline10 mentions / 7d
01223Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Mentions · 2026-05-14: 1Mentions · 2026-05-21: 3Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-21: 3Technical Details · 2026-04-30: 1Technical Details · 2026-05-21: 304-2304-2404-2604-3005-0105-1405-21
Signal classification4 categories
General
440.0%
Patch
330.0%
Disclosure
220.0%
Active Exploitation
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-231
General1
2026-04-241
General1
2026-04-261
General1
2026-04-302
Disclosure1Patch1
2026-05-011
General1
2026-05-141
Disclosure1
2026-05-213
Active Exploitation1Patch2
Full discourse10 posts
  • S2GRUPO@s2grupo
    Patch

    Vulnerabilidades CVE-2026-6919 y CVE-2026-6920 afectan a componentes internos del motor del navegador Google Chrome. Se recomienda actualizar a la versión 147.0.7727.117 o superior. https://hubs.la/Q04dK0bR0

    Post summary

    The advisory announces new CVEs affecting Chrome’s internal engine components and recommends updating to at least version 147.0.7727.117 to mitigate the risk.

    00031259
    5.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Chrome DevTools Sandbox Escape (CVE-2026-6919): 3.5B Users Face Active Exploitation Risk Google's Chrome team issued a security update on April 24-25, 2026, addressing 19 internal security defects, three of which were assigned CVE identifiers.

    Post summary

    Google released a security update on 24‑25 April 2026 to address CVE‑2026‑6919, a DevTools sandbox escape that could affect 3.5 B users; a patch is available, but no evidence of active exploitation is provided.

    1000042
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Google patched three browser vulnerabilities in Chrome 147.0.7727.116+, including CVE-2026-6919, a HIGH-severity use-after-free in DevTools that enables sandbox escape via malicious web pages. Exploitation could grant remote code execution. Updates rolling out over…

    Post summary

    Google announced a patch for CVE-2026-6919, a high-severity use-after-free in Chrome 147.0.7727.116+ that could lead to remote code execution via malicious web pages.

    1000056
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    90% · CVE-2026-6919 · 147.0.7727.116 → 147.0.7727.117 Chrome DevTools Sandbox Escape (CVE-2026-6919): 3.5B Users Face Active Exploitation Risk

    Post summary

    Chrome’s DevTools Sandbox Escape (CVE‑2026‑6919) is actively being exploited across roughly 3.5 B users, and a patch is available in the new 147.0.7727.117 update.

    1000047
    226 followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    General

    被害防止に役立つクローム脆弱性ポイント、押さえておきたい 【脆弱性情報】 CVE-2026-6919 googleのchromeの脆弱性について https://www.cybernote.click/2026/04/26/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6919-google%e3%81%aechrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-6919-google%25e3%2581%25aechrome%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post merely references a blog article about CVE‑2026‑6919, with no additional information on exploitation, patches, or technical details.

    0001092
    210 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    グーグルクロームの脆弱性を解説。安全に今すぐ対策を確認しよう! 【脆弱性情報】 CVE-2026-6919 googleのchromeの脆弱性について https://www.cybernote.click/2026/04/26/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6919-google%e3%81%aechrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-6919-google%25e3%2581%25aechrome%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The text announces a new Chrome vulnerability (CVE‑2026‑6919) and directs readers to a link for more information.

    0000085
    211 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-6919 | Chromium: CVE-2026-6919 Use after free in DevTools | Rahsi Framework™ https://www.aakashrahsi.online/post/cve-2026-6919 https://t.co/Ja8l91aYEN

    Post summary

    An announcement of CVE-2026-6919, a use‑after‑free vulnerability in Chromium's DevTools, with no evidence of active exploitation or mitigation details provided.

    0000016
    1 followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    General

    【 #脆弱性情報】 CVE-2026-6919 #google の #chrome の脆弱性について https://www.cybernote.click/2026/04/26/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6919-google%e3%81%aechrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/

    Post summary

    The tweet only references a Google Chrome vulnerability (CVE-2026-6919) and links to an external source without providing additional details.

    0000065
    210 followersView on X
  • haeretics@略称ヘレ@haeretics
    General

    CVE番号が付番されたのは以下の3件 CVE-2026-6919:High(深刻度) CVE-2026-6920:High CVE-2026-6921:Medium

    Post summary

    The text merely lists three CVE identifiers with their severity ratings, without providing additional context or technical information.

    0000067
    472 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-6919) https://vuldb.com/vuln/359166

    Post summary

    The post merely announces the existence of CVE‑2026‑6919 with high criticality, without providing evidence of PoC, exploits, or mitigation.

    0000076
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more