Google Chrome Script Injection Vulnerability in UI

Vulnerability

A vulnerability allowing script injection in the user interface has been identified in Google Chrome versions prior to 148.0.7778.96. This issue, classified as a user-experience cross-site scripting (UXSS) vulnerability, allowed remote attackers to inject arbitrary scripts or HTML by convincing users to perform specific UI gestures on a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to user-experience cross-site scripting, allowing for the injection of scripts that could be executed in the context of the user's session.

Remediation

Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.

Added: May 6, 2026, 7:21 PM
Updated: May 6, 2026, 7:21 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.2
remediation
7.7
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.