8.6
CVE-2026-19143
- EPSS 0.13%
- Veröffentlicht 06.08.2026 22:16:56
- Zuletzt bearbeitet 08.08.2026 05:17:07
- CVE-Watchlists
- Unerledigt
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.028 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.6 | 1.8 | 6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html
https://issues.chromium.org/issues/517772612