Description
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug arises from an inadequate processing of CSS in older Chrome versions, letting an attacker embed arbitrary scripts or HTML into a page through a specially crafted web document. This flaw facilitates a user interface cross‑site scripting attack, permitting the execution of attacker‑controlled code in the victim’s browser context and potentially exfiltrating data or performing malicious actions on the user’s behalf. The weakness is formally cataloged as CWE‑79.

Affected Systems

Google Chrome browsers prior to version 151.0.7922.72 are affected. Any installation of Chrome before this release, regardless of operating system or language pack, is vulnerable unless patched.

Risk and Exploitability

The CVSS score of 6.1 reflects a moderate severity, while an EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires only a crafted HTML page accessible to the user, making it a remote attack vector that is feasible through social engineering or malicious websites. The impact is limited to the user context; there is no direct privilege escalation or system compromise.

Generated by OpenCVE AI on August 2, 2026 at 06:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or newer, which contains the CSS processing fix.
  • Configure browsers to receive automatic updates so that future fixes are applied without manual intervention.
  • If an immediate upgrade is not possible, consider restricting untrusted content using a Content‑Security‑Policy or operating a separate, sandboxed browsing environment.

Generated by OpenCVE AI on August 2, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in CSS
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T18:25:56.128Z

Reserved: 2026-07-27T23:35:10.282Z

Link: CVE-2026-17878

cve-icon Vulnrichment

Updated: 2026-07-30T18:25:49.338Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:51.743

Modified: 2026-08-03T17:37:34.880

Link: CVE-2026-17878

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:46Z

Links: CVE-2026-17878 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')