Description
Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient validation of untrusted cookie input within the browser allows a remote attacker to create a malicious HTML page that is treated as trustworthy by Chrome. The flaw enables privilege escalation within the Chrome process, potentially giving the attacker higher rights than the user’s normal sandbox permits. The vulnerability is rooted in CWE-20, highlighting improper input validation. The effect is a privilege escalation that can compromise data integrity and confidentiality on the affected host.

Affected Systems

All desktop editions of Google Chrome older than version 148.0.7778.96 are impacted. The flaw is present on the stable channel for Windows, macOS, and Linux, where cookie parsing has not yet received the mitigation. Versions 148.0.7778.96 and later contain the necessary input validation fixes.

Risk and Exploitability

The CVSS score is 8.8, indicating a high severity level. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a malicious webpage that the victim visits; therefore, the attack vector is Remote. While the vulnerability does not provide direct remote code execution, the privilege escalation potential makes it a significant risk if an attacker can persuade a user to load the crafted HTML.

Generated by OpenCVE AI on May 7, 2026 at 01:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.96 or later, which includes the patch for cookie input validation.
  • If an update cannot be applied immediately, disable third‑party cookies through Chrome’s settings or via an enterprise policy to reduce the attack surface.
  • Use a browser policy to block websites that have not been updated or that are known to serve malicious content until the patch is available.

Generated by OpenCVE AI on May 7, 2026 at 01:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Cookies Validation Privilege Escalation in Google Chrome

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cookies Validation Privilege Escalation in Google Chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:52.635Z

Reserved: 2026-05-05T22:59:12.653Z

Link: CVE-2026-7930

cve-icon Vulnrichment

Updated: 2026-05-06T20:48:00.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:41.343

Modified: 2026-05-06T23:36:52.777

Link: CVE-2026-7930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:15:17Z

Weaknesses