Script Injection Vulnerability in Google Chrome by Google
CVE-2026-8021

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-8021?

A vulnerability exists in Google Chrome prior to version 148.0.7778.96 that can be exploited through specially crafted HTML pages. This allows a remote attacker to execute arbitrary scripts by tricking users into engaging with specific UI gestures. This poses a risk as it can lead to unauthorized actions within the browser environment, impacting user privacy and data integrity.

Affected Version(s)

Chrome 148.0.7778.96

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.