PT-2026-38146 · Google · Google Chrome

Published

2026-03-26

·

Updated

2026-05-14

·

CVE-2026-7953

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 148.0.7778.96
Description Insufficient validation of untrusted input in the Omnibox allows a remote attacker to inject arbitrary scripts or HTML, leading to Universal Cross-Site Scripting (UXSS), which is a vulnerability that allows scripts to execute across different origins. This can be achieved via malicious network traffic.
Recommendations Update to version 148.0.7778.96 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-07066
CVE-2026-7953
ECHO-7B95-8480-5B68
OPENSUSE-SU-2026:10778-1

Affected Products

Google Chrome