Insufficient Input Validation in Google Chrome Extensions
CVE-2026-16415

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-16415?

A vulnerability in Google Chrome's Extensions prior to version 150.0.7871.182 enables remote attackers to exploit insufficient validation of untrusted input. This flaw allows attackers to manipulate the Omnibox (URL bar) by delivering specially crafted HTML pages. By leveraging this weakness, an attacker could display misleading information in the URL bar, potentially leading users to believe they are interacting with a legitimate source while in reality, they are being deceived.

Affected Version(s)

Chrome 150.0.7871.182

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.