Junglewise Threat Intelligence

CVE-2026-13977: Google Chrome UXSS in HTMLParser

CVE-2026-13977 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its HTML parsing component could allow a malicious website to bypass security boundaries and run unauthorized scripts in the context of other websites. This could lead to the theft of sensitive information or unauthorized actions on behalf of the user.

Technical details

An inappropriate implementation in the HTMLParser component of Google Chrome prior to version 150.0.7871.47 allowed for Universal Cross-Site Scripting (UXSS). By enticing a user to visit a specially crafted HTML page, a remote attacker could bypass the Same-Origin Policy (SOP) to inject and execute arbitrary scripts or HTML in the context of any website. This vulnerability is triggered during the parsing of HTML content. The issue has been addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats