Description
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An oversight in how Google Chrome processes untrusted input from extensions allows a malicious extension to manipulate the text shown in the Omnibox, the browser’s URL bar. The flaw is an instance of insufficient input validation (CWE‑20). If exploited, a user can be misled into believing they are viewing a trusted site, potentially resulting in credential theft or delivery of fraudulent content.

Affected Systems

Google Chrome browsers on any operating system running a version earlier than 150.0.7871.182 are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating medium severity, and an EPSS score of less than 1%, suggesting a low likelihood of exploitation. It is not listed in CISA KEV. The likely attack vector involves a malicious Chrome extension in combination with a crafted HTML page, inferred from the description; no elevated privileges are required, inferred because the vulnerability is described as affecting untrusted extension input. Exploitation would require a user to visit the crafted page, after which the spoofed URL bar may redirect them to a phishing site or other malicious destination.

Generated by OpenCVE AI on August 4, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.182 or later to apply the vendor’s fix for this input validation flaw.
  • Disable or uninstall any Chrome extensions that are unnecessary or come from untrusted sources to reduce the attack surface.
  • Ensure Chrome’s Safe Browsing and phishing protection are enabled to help detect deceptive URLs, though this is a complementary measure.

Generated by OpenCVE AI on August 4, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Omnibox Spoofing via Untrusted Extension Input

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome Omnibox Spoofing via Untrusted Extension Input

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome Omnibox Spoofing via Untrusted Extension Input
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-24T12:49:58.291Z

Reserved: 2026-07-20T22:23:05.416Z

Link: CVE-2026-16415

cve-icon Vulnrichment

Updated: 2026-07-24T12:49:50.387Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation