Junglewise Threat Intelligence

CVE-2026-15128: Google Chrome UXSS in Forms

CVE-2026-15128 · Severity: info · CVSS 8.8 · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser handles web forms allows a remote attacker to execute malicious scripts or inject arbitrary HTML content when a user visits a specially crafted webpage. This could lead to the theft of sensitive information, such as login credentials or session cookies, from other websites the user has open.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Forms component of Google Chrome due to an inappropriate implementation. By enticing a user to visit a specially crafted HTML page, a remote attacker can bypass the Same-Origin Policy (SOP) to inject and execute arbitrary scripts or HTML in the context of any website. This allows for the compromise of data across different origins, potentially leading to full account takeover or sensitive data exfiltration. The vulnerability is addressed in Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-06-14: disclosed: Reported by Google internally
  • 2026-07-08: patched: Fixed in stable channel update 150.0.7871.115
  • 2026-07-08: advisory

References

Related threats