Google Chrome Service Worker Inappropriate Implementation Vulnerability Allowing User-Installed Extension Script Injection

Vulnerability

A vulnerability exists in Google Chrome in the Service Worker component, prior to version 148.0.7778.96. This issue allows an attacker to inject arbitrary scripts or HTML, leading to a user experience spoofing vulnerability, by convincing a user to install a malicious extension.

Impact

Exploitation of this vulnerability could result in user experience spoofing, allowing for the injection of arbitrary scripts or HTML.

Remediation

Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.

Added: May 6, 2026, 8:14 PM
Updated: May 6, 2026, 8:14 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.2
remediation
7.7
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.