Skip to content
Threat Feed
high advisory

Chromium Use-After-Free in Extensions

A use-after-free vulnerability in the Chromium Extensions component allows for potential arbitrary code execution or application instability across affected browsers.

CVE search metadata

CVE search record: CVE-2026-19558. Severity: high. CVSS: 7.5. EPSS: 0.23%. KEV: no. Product: Chrome, Edge. Brief: Chromium Use-After-Free in Extensions. Brief link: https://feed.craftedsignal.io/briefs/2026-08-chromium-uaf-extensions/

Chromium has disclosed a high-severity use-after-free vulnerability, tracked as CVE-2026-19558, located within the Extensions component of the Chromium browser engine. This vulnerability impacts both Google Chrome and Microsoft Edge, as the latter utilizes the Chromium engine for its core browsing functionality. A use-after-free vulnerability occurs when an application continues to use a memory pointer after it has been freed, which can lead to memory corruption, browser crashes, or the potential for an attacker to execute arbitrary code within the context of the application. Given the prevalence of browser-based web access in enterprise environments, this vulnerability poses a significant risk if exploited by malicious web content. Defenders should monitor for browser update releases from both Google and Microsoft to ensure their environments are patched against this memory management flaw.

Impact

Successful exploitation of CVE-2026-19558 could allow an attacker to achieve arbitrary code execution on the host machine or cause persistent browser instability. The impact is significant for organizations relying on web-based business applications, as the vulnerability is triggered via browser extensions or malicious web interactions.

Recommendation

Prioritize the deployment of browser updates for both Google Chrome and Microsoft Edge to the latest versions that include the fix for CVE-2026-19558. Implement automated patch management for all endpoint browsers to ensure that security updates are applied immediately upon release. Verify the version numbers of deployed browsers across the fleet to identify and remediate instances where automatic updates may have failed.


Immediate actions

Update all instances of Google Chrome and Microsoft Edge to the latest patched version.

IT Operations 48h

Mitigations

Enable automatic browser updates across all managed endpoints.

immediate IT Operations

CVE-2026-19558