Description
Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper implementation of Chrome’s HTMLParser in versions prior to 150.0.7871.47 permits a remote attacker to inject arbitrary scripts or HTML into a crafted web page. This flaw allows cross‑site scripting attacks by failing to isolate malicious markup, enabling the execution of injected code in the context of the victim’s browser.

Affected Systems

All builds of Google Chrome older than 150.0.7871.47 are affected, regardless of the operating system. The vulnerability exists on any Chrome distribution that ships with those versions.

Risk and Exploitability

The EPSS score of less than 1% indicates an extremely low probability of real‑world exploitation, and the flaw is not listed in CISA’s KEV catalog. The CVSS score of 5.4 reflects a medium impact. Based on the description, the most likely attack vector is delivering a crafted page from a malicious website, email link, or attachment. Even so, the low EPSS and medium severity suggest that the overall exploitation risk remains minimal.

Generated by OpenCVE AI on July 31, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later to apply the HTMLParser fix.
  • Enable and monitor Chrome’s auto‑update feature so updates are installed automatically.
  • Implement a strict content‑script loading policy or CSP to mitigate potential XSS if other vulnerabilities exist.

Generated by OpenCVE AI on July 31, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Vulnerability Allows Remote Script Injection

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Vulnerability Allows Remote Script Injection

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via HTMLParser in Google Chrome

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via HTMLParser in Google Chrome

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Chrome's HTML Parser

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Chrome's HTML Parser

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Vulnerability Allowing Remote XSS via Crafted Pages

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Vulnerability Allowing Remote XSS via Crafted Pages

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Chrome’s HTMLParser

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Chrome’s HTMLParser

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting via HTMLParser in Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting via HTMLParser in Chrome

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title User-Interface XSS via Chrome HTMLParser Improper Script Sanitization

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title User-Interface XSS via Chrome HTMLParser Improper Script Sanitization

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Cross‑site Scripting Vulnerability

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome HTMLParser Cross‑site Scripting Vulnerability

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title HTMLParser Vulnerability Allowing Script Injection in Chrome

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title HTMLParser Vulnerability Allowing Script Injection in Chrome

Thu, 02 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Insecure HTML Parser Enables Cross‑Site Scripting in Chrome

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Insecure HTML Parser Enables Cross‑Site Scripting in Chrome

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title HTMLParser Vulnerability Enabling Arbitrary Script Injection
Weaknesses CWE-79

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title HTMLParser Vulnerability Enabling Arbitrary Script Injection
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:29:56.455Z

Reserved: 2026-06-29T23:04:06.570Z

Link: CVE-2026-13977

cve-icon Vulnrichment

Updated: 2026-07-01T19:29:51.825Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')