Executive brief
This entry was originally reported as a security issue in the Google Chrome web browser but has since been rejected by the maintainers. It was determined to be a functional bug rather than a security vulnerability. As such, it does not pose a direct risk of unauthorized data access or system compromise beyond standard software instability.
Technical details
This CVE (CVE-2026-7930) has been officially rejected by the vendor. The original report cited insufficient validation of untrusted input in Cookies within Google Chrome prior to version 148.0.7778.96, which was initially thought to allow privilege escalation via a crafted HTML page. Upon further review, the Chromium team reclassified the issue as a 'feature bug' rather than a security vulnerability. All associated CVSS scores and CWE mappings have been removed from the official record.
Affected products
- Google Chrome prior to 148.0.7778.96
Timeline
- 2026-05-06: disclosed: Initial publication of the CVE record.
- 2026-06-10: other: CVE marked as Rejected by the vendor.