CVE-2026-7958
ServiceWorker UXSS in Google Chrome
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 148.0.7778.96 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the ServiceWorker component of Google Chrome versions prior to 148.0.7778.96. It allows an attacker who convinces a user to install a malicious Chrome extension to inject arbitrary scripts or HTML content. This type of attack is known as UXSS (Universal Cross-Site Scripting).
How can this vulnerability impact me? :
If exploited, this vulnerability can allow an attacker to execute arbitrary scripts or inject HTML in the context of the browser. This can lead to unauthorized actions, data theft, or manipulation of web content viewed by the user.