Description
Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in WebGL handling within Google Chrome before version 150.0.7871.115 allows an attacker to inject arbitrary scripts or HTML via a crafted webpage. This injection enables the execution of malicious code directly in the victim’s browser context while the user interacts with the page.

Affected Systems

All users of Google Chrome whose browser version is earlier than 150.0.7871.115 are affected. The vulnerability applies specifically to the Chrome product distributed by Google.

Risk and Exploitability

The likely attack vector is delivering a maliciously crafted HTML page to a user, as inferred from the description that a remote attacker can inject scripts via a crafted page. The vulnerability can be triggered remotely by visiting such a page; no user credentials or special access are required beyond a standard web visit. The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 6.1 reflects medium severity. The flaw is not listed in CISA’s KEV catalog. Any user browsing the page could be impacted.

Generated by OpenCVE AI on July 28, 2026 at 09:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.115 or later to receive the official fix
  • Disable WebGL via Chrome flags (chrome://flags) or by using a browser extension as a temporary workaround
  • Apply a strict Content Security Policy to sites that render user‑generated content to reduce the impact of any remaining injection vectors

Generated by OpenCVE AI on July 28, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title WebGL Script Injection Vulnerability in Chrome

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title WebGL Script Injection Leading to UXSS in Chrome

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title WebGL Script Injection Leading to UXSS in Chrome

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Inappropriate WebGL Implementation Enables Remote Script Injection in Chrome

Tue, 14 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Inappropriate WebGL Implementation Enables Remote Script Injection in Chrome

Sat, 11 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title WebGL Injection Allowing Script Execution in Google Chrome Before 150.0.7871.115

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title WebGL Injection Allowing Script Execution in Google Chrome Before 150.0.7871.115

Thu, 09 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title WebGL Arbitrary Script Injection in Google Chrome

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title WebGL Arbitrary Script Injection in Google Chrome
Weaknesses CWE-79

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:15:03.155Z

Reserved: 2026-07-08T17:07:43.731Z

Link: CVE-2026-15127

cve-icon Vulnrichment

Updated: 2026-07-09T10:14:58.677Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')