Description
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-05-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the handling of MHTML files in Google Chrome versions prior to 148.0.7778.96. Through a crafted HTML page, an attacker who has already compromised the renderer process can inject arbitrary scripts or HTML, thereby executing malicious code in the context of the renderer. This cross‑domain injection can lead to the compromise of the user’s data and, depending on the sandbox configuration, potentially further privilege escalation.

Affected Systems

Google Chrome is affected. Any installation using a version older than 148.0.7778.96 is susceptible. The vulnerability is tied specifically to the MHTML handling component of the rendering engine.

Risk and Exploitability

The CVSS score is 5.4, and no EPSS value is available, so the quantitative likelihood is unknown. The vulnerability is not listed in CISA’s KEV catalog, indicating no widely‑known exploits at present. However, the attack requires an initial compromise of the renderer process, meaning the risk is higher for targeted attacks that can achieve in‑process exploitation. The overall risk remains moderate, with the potential impact escalating if sandbox boundaries are breached.

Generated by OpenCVE AI on May 7, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.96 or later.
  • Ensure that the local Chrome sandbox remains enforced.
  • Monitor for anomalous renderer process activity.

Generated by OpenCVE AI on May 7, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 00:45:00 +0000

Type Values Removed Values Added
Title MHTML Processing Vulnerability Enabling Arbitrary Script Injection in Google Chrome

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 21:00:00 +0000

Type Values Removed Values Added
Title MHTML Processing Vulnerability Enabling Arbitrary Script Injection in Google Chrome
Weaknesses CWE-79

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:46:43.814Z

Reserved: 2026-05-05T22:59:34.807Z

Link: CVE-2026-8012

cve-icon Vulnrichment

Updated: 2026-05-06T21:14:34.592Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:52.160

Modified: 2026-05-07T15:19:48.613

Link: CVE-2026-8012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T00:30:12Z

Weaknesses