Junglewise Threat Intelligence

CVE-2026-13836: Google Chrome UXSS in CSS implementation

CVE-2026-13836 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles CSS (Cascading Style Sheets) could allow a malicious website to bypass security boundaries and run unauthorized scripts or HTML in the context of other websites. This could lead to the theft of sensitive information, such as login credentials or session cookies, from other sites the user has open.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS implementation. The flaw stems from an inappropriate implementation that allows a remote attacker to bypass the Same-Origin Policy (SOP) by enticing a user to visit a specially crafted HTML page. Successful exploitation enables the attacker to inject and execute arbitrary scripts or HTML within the context of any website currently loaded in the browser. This vulnerability was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats