PT-2026-38151 · Google · Google Chrome

Published

2026-03-26

·

Updated

2026-05-14

·

CVE-2026-7958

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 148.0.7778.96
Description An inappropriate implementation in ServiceWorker allows an attacker to inject arbitrary scripts or HTML (Universal Cross-Site Scripting - UXSS, a vulnerability where an attacker can execute scripts across different origins) via a crafted Chrome Extension, provided they can convince a user to install a malicious extension.
Recommendations Update to version 148.0.7778.96 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-07073
CVE-2026-7958
ECHO-ABBC-98E7-276E
OPENSUSE-SU-2026:10778-1

Affected Products

Google Chrome