Description
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect CSS handling routine in Google Chrome versions prior to 150.0.7871.47 permits a remote attacker to inject arbitrary scripts or HTML when a crafted web page is loaded. The result is a form of User‑Experience Cross‑site Scripting that allows the attacker to execute code in the victim’s browser context, though it does not grant system‑level privileges.

Affected Systems

All desktop installations of Google Chrome running a version earlier than 150.0.7871.47 are vulnerable. The issue applies to the stable channel, but this assumption is inferred from the release notes and is not explicitly stated in the advisory. Standard consumer users who have not applied the latest security update are at risk.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been documented. The CVSS score of 6.1 classifies it as low severity from the Chromium perspective, yet the attack vector is remote and requires a victim to visit a maliciously crafted page. Timely remediation is important to prevent potential exploitation.

Generated by OpenCVE AI on July 17, 2026 at 13:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer, which contains the fix for the CSS injection.
  • If an update cannot be applied immediately, enforce a strict Content‑Security‑Policy to block unauthorized script execution and disable third‑party scripts to mitigate UXSS risk.
  • Monitor Chrome release notes and security advisories for future updates and new vulnerability mitigations.

Generated by OpenCVE AI on July 17, 2026 at 13:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title CSS Injection Leading to User‑Experience Cross‑Site Scripting in Google Chrome

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title CSS Injection Leading to User‑Experience Cross‑Site Scripting in Google Chrome

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Injection Allows Remote Script Execution via UXSS

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Chrome CSS Injection Allows Remote Script Execution via UXSS

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote CSS‑based HTML Injection Allows XSS in Google Chrome

Fri, 10 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote CSS‑based HTML Injection Allows XSS in Google Chrome

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Script Injection via Improper CSS Handling in Chrome

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Script Injection via Improper CSS Handling in Chrome

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chromium CSS Injection Leading to UXSS Vulnerability

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chromium CSS Injection Leading to UXSS Vulnerability

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote UXSS via CSS Injection in Google Chrome

Sun, 05 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote UXSS via CSS Injection in Google Chrome

Sun, 05 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Injection Enables User‑Experience Cross‑Site Scripting

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome CSS Injection Enables User‑Experience Cross‑Site Scripting

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title CSS Injection Leading to User‑Experience Cross‑Site Scripting in Google Chrome

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title CSS Injection Leading to User‑Experience Cross‑Site Scripting in Google Chrome

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Google Chrome CSS Injection Enables Remote UXSS

Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Google Chrome CSS Injection Enables Remote UXSS

Thu, 02 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title CSS Handling Vulnerability in Google Chrome Allows UXSS

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title CSS Handling Vulnerability in Google Chrome Allows UXSS

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Remote Script Injection via CSS Bug in Google Chrome

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Script Injection via CSS Bug in Google Chrome

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Inappropriate CSS Implementation Enables Remote Script Injection in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Inappropriate CSS Implementation Enables Remote Script Injection in Chrome
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T13:59:10.570Z

Reserved: 2026-06-29T23:11:51.277Z

Link: CVE-2026-14147

cve-icon Vulnrichment

Updated: 2026-07-01T13:58:19.175Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')