Junglewise Threat Intelligence

CVE-2026-8539: Google Chrome script injection in SanitizerAPI

CVE-2026-8539 · Severity: medium · CVSS 5.4 · Published 2026-05-14

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android's SanitizerAPI allowed malicious websites to bypass security protections and inject unauthorized scripts or HTML. This could lead to Universal Cross-Site Scripting (UXSS), potentially allowing an attacker to steal user data or perform actions on behalf of the user across different websites. Users are advised to update their Chrome browser to version 148.0.7778.168 or later to mitigate this risk.

Technical details

A script injection vulnerability exists in the SanitizerAPI component of Google Chrome on Android. The flaw is caused by improper control of generation of code (CWE-94), which allows a remote attacker to bypass the sanitizer's intended restrictions. By convincing a user to visit a specially crafted HTML page, an attacker can achieve Universal Cross-Site Scripting (UXSS). This enables the execution of arbitrary JavaScript in the context of any site the user is visiting. The issue was addressed in Chrome version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-26: disclosed: Reported by Jungwoo Lee and Wongi Lee
  • 2026-05-12: patched: Stable channel update released
  • 2026-05-14: advisory: NVD publication date

References

Related threats