Description
Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-05-06
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome browsers before 148.0.7778.96 suffer from a script injection flaw that allows a remote attacker, through a crafted HTML page, to inject arbitrary scripts or HTML into the UI. This flaw, identified as a form of UXSS, can lead to malicious code execution within the context of the page or the user's interaction, potentially enabling phishing, data theft, or other browser-based attacks. The weakness corresponds to CWE‑94, describing improper neutralization of input during web page generation.

Affected Systems

All desktop installations of Google Chrome running any version earlier than 148.0.7778.96 are vulnerable. The flaw applies to standard Chrome builds for Windows, macOS, Linux, and other supported desktop platforms. The product is the standard Google Chrome browser used via the stable channel.

Risk and Exploitability

The issue has a low severity rating from Chromium’s internal evaluation. Exploitation requires the victim to load a maliciously crafted page and perform specific UI gestures to activate the injection; the attacker must obtain the user’s attention and willingness to interact. Chromiums CVSS score of 4.2 underscores the low severity classification for this vulnerability. Because the vulnerability is not listed in the CISA KEV catalog and the EPSS score is not available, the likelihood of widespread exploitation is currently unclear, but the exposed capability could be leveraged in targeted social‑engineering attacks. Users with unpatched Chrome versions are therefore at risk, particularly those who frequently visit unfamiliar sites or handle untrusted media.

Generated by OpenCVE AI on May 7, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 148.0.7778.96 or later
  • Ensure automatic updates are enabled or manually check for the latest Chrome release
  • Use the browser’s content settings to block JavaScript on untrusted sites or employ a reputable script blocker extension

Generated by OpenCVE AI on May 7, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 07 May 2026 00:45:00 +0000

Type Values Removed Values Added
Title Script Injection in Chrome UI Enables Arbitrary Script Execution

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-94
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:45:25.784Z

Reserved: 2026-05-05T22:59:37.132Z

Link: CVE-2026-8021

cve-icon Vulnrichment

Updated: 2026-05-06T20:52:55.020Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-06T19:16:53.053

Modified: 2026-05-06T22:16:46.960

Link: CVE-2026-8021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:30:17Z

Weaknesses