Description
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Chrome’s Network module and allows a remote attacker to inject arbitrary script or HTML into the browser’s user interface through a specially crafted HTML page. This is a CWE‑79 flaw that can lead to execution of malicious code in the context of the browser, enabling the attacker to hijack user sessions, exfiltrate data, or modify page content. The flaw does not require elevated privileges; it can be triggered simply by a user visiting the fake page, making the integrity of the UI and any data processed by the browser at risk.

Affected Systems

Any installation of Google Chrome running a version older than 150.0.7871.47 on any operating system, including stable channel users, is vulnerable. The issue affects all users who might browse a malicious site that serves the crafted page.

Risk and Exploitability

The CVSS score of 6.1 classifies the flaw as moderate. The EPSS score of less than 1% indicates that attacks are currently rare but possible. Because the vulnerability can be triggered through ordinary web browsing without special access, it can potentially affect all users who visit a malicious page. The flaw is not currently listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet.

Generated by OpenCVE AI on July 31, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to 150.0.7871.47 or a later version
  • Configure the browser or extensions to block inline or remote script execution on untrusted sites
  • Apply or enable any available content‑security‑policy extensions that restrict script loading

Generated by OpenCVE AI on July 31, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome UXSS Allowing Injection of Arbitrary Scripts Through Crafted HTML

Sat, 25 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chromium Secure Network Module UXSS Vulnerability in Chrome 150.0.7871.47 and Earlier

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chromium Secure Network Module UXSS Vulnerability in Chrome 150.0.7871.47 and Earlier

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Network Module UI Cross‑Site Scripting Vulnerability

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Module UI Cross‑Site Scripting Vulnerability

Mon, 13 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Google Chrome UXSS via Network Module

Sun, 12 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Google Chrome UXSS via Network Module

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome UXSS via crafted HTML page

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome UXSS via crafted HTML page

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Google Chrome Allows Script Injection via Network Module

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Google Chrome Allows Script Injection via Network Module

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Module Vulnerability Allows Remote UXSS via Crafted Webpage

Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Chrome Network Module Vulnerability Allows Remote UXSS via Crafted Webpage

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title User Interface XSS in Google Chrome Network Module

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title User Interface XSS in Google Chrome Network Module

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome UXSS via Network Module Injection

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome UXSS via Network Module Injection

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Google Chrome User Interface Cross‑Site Scripting via Network Module

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Google Chrome User Interface Cross‑Site Scripting via Network Module

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title User Interface Cross‑Site Scripting via Network Module in Google Chrome

Thu, 02 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title User Interface Cross‑Site Scripting via Network Module in Google Chrome

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Google Chrome Network Module

Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Google Chrome Network Module

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Google Chrome UXSS via Network Module
Weaknesses CWE-79

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Google Chrome UXSS via Network Module
Weaknesses CWE-79

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Inappropriate Network Implementation Enables Remote UI XSS in Google Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Inappropriate Network Implementation Enables Remote UI XSS in Google Chrome
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:05:44.219Z

Reserved: 2026-06-29T23:04:15.061Z

Link: CVE-2026-14001

cve-icon Vulnrichment

Updated: 2026-07-01T14:48:30.666Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')