Google Chrome Omnibox Untrusted Input Validation Vulnerability Allowing UXSS

Vulnerability

A vulnerability in Google Chrome's Omnibox feature, present in versions prior to 148.0.7778.96, allowed remote attackers to inject arbitrary scripts or HTML, leading to a cross-site scripting vulnerability that could be exploited through malicious network traffic. This issue arose from insufficient validation of untrusted input.

Impact

Exploitation of this vulnerability could lead to a cross-site scripting vulnerability, allowing for the injection of scripts or HTML that could be executed in the context of the user's browser.

Remediation

Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.

Added: May 6, 2026, 8:18 PM
Updated: May 6, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.4
remediation
7.7
relevance
7.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.