Description
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate handling of untrusted content in Google Chrome’s ServiceWorker implementation allows a malicious extension, if installed, to inject arbitrary scripts or HTML into pages that the user visits. The vulnerability is associated with CWE‑79 and is rated medium severity by Chromium. Based on the description, it is inferred that such injected scripts could deface pages, redirect users, or exfiltrate sensitive data that the page presents, although those specific exploitation outcomes are not explicitly stated in the advisory.

Affected Systems

Google Chrome installations any build earlier than 148.0.7778.96 are affected, including the stable desktop channel. All users who have default or unverified extensions installed on these builds are at risk.

Risk and Exploitability

The exploit requires social engineering to convince a user to add a malicious extension. Once installed, the extension can run scripts with the privileges of the affected browser instance. No public exploitation has been reported, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.4 reflects a medium severity level, and the risk is heightened for enterprises with unmanaged extension policies.

Generated by OpenCVE AI on May 7, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 148.0.7778.96 or later to eliminate the improper ServiceWorker handling
  • Disable or remove any untrusted or suspicious Chrome extensions
  • Configure enterprise policy to allow only whitelisted extensions and monitor for new installations

Generated by OpenCVE AI on May 7, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 03:45:00 +0000

Type Values Removed Values Added
Title ServiceWorker XSS via Malicious Chrome Extension

Thu, 07 May 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title ServiceWorker UI Script Injection Vulnerability in Chrome
Weaknesses CWE-116

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:00:00 +0000

Type Values Removed Values Added
Title ServiceWorker UI Script Injection Vulnerability in Chrome
Weaknesses CWE-116
CWE-79

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:55:20.944Z

Reserved: 2026-05-05T22:59:20.195Z

Link: CVE-2026-7958

cve-icon Vulnrichment

Updated: 2026-05-06T21:39:36.602Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:45.693

Modified: 2026-05-07T02:05:24.340

Link: CVE-2026-7958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T03:30:20Z

Weaknesses