CVE-2026-8012
Inappropriate Implementation in MHTML in Google Chrome Allows UXSS
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 148.0.7778.96 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the MHTML feature of Google Chrome versions prior to 148.0.7778.96. It allows a remote attacker who has already compromised the renderer process to inject arbitrary scripts or HTML content through a specially crafted HTML page. This type of attack is known as Universal Cross-Site Scripting (UXSS).
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to execute arbitrary scripts or inject malicious HTML in the context of the affected browser. This could lead to unauthorized actions such as stealing sensitive information, manipulating web content, or performing actions on behalf of the user within the compromised renderer process.