Expired Pointer Dereference Affecting chromium package, versions [,151.0.7922.109)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CHROMIUM-18600483
  • published9 Aug 2026
  • disclosed6 Aug 2026
  • creditUnknown

Introduced: 6 Aug 2026

NewCVE-2026-19155  (opens in a new tab)
CWE-825  (opens in a new tab)

How to fix?

Upgrade chromium to version 151.0.7922.109 or higher.

Overview

Affected versions of this package are vulnerable to Expired Pointer Dereference via the Payments process. An attacker can gain elevated privileges and potentially compromise the underlying system by enticing a user to visit a specially crafted HTML page after first compromising the renderer process. This is only exploitable if the attacker has already achieved code execution within the renderer process.

Workaround

This vulnerability can be mitigated by avoiding visits to untrusted or suspicious websites and employing browser sandboxing mechanisms to contain potential compromises.

CVSS Base Scores

version 4.0
version 3.1