Junglewise Threat Intelligence

CVE-2026-13957: Google Chrome UXSS in Extensions via incorrect security UI

CVE-2026-13957 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security flaw in Google Chrome's extension interface could allow a malicious extension to bypass security boundaries. If a user is tricked into installing a specially crafted extension, an attacker could execute unauthorized scripts or display fake content on other websites. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user.

Technical details

This vulnerability is classified as a Universal Cross-Site Scripting (UXSS) issue resulting from an incorrect security UI implementation within the Extensions component of Google Chrome. The flaw allows a malicious extension, once installed by a user, to bypass the Same-Origin Policy (SOP) by leveraging a crafted HTML page to inject arbitrary scripts or HTML into other origins. The attack requires user interaction to install the malicious extension. Google has addressed this issue in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats