CVE-2026-79234
Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-74
- Published
- 2026-08-25
- Last modified
- 2026-08-26
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-87572 — Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer
- CVE-2026-82971 — QVidium Opera11 CGI Script net_tr.cgi command injection
- CVE-2026-20130 — Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities
- CVE-2026-12351 — IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
- CVE-2026-79697 — Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
- CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
- CVE-2026-83772 — Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection
- CVE-2026-83524 — RedPort Optimizer wXa-223 System Clock datetime.php exec command injection