CVE-2026-0628
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
- Affected products
- Debian, Google Chrome, Red Os
- Google Chrome
- < 143.0.7499.192
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 6.7% (93th percentile)
- Weakness
- CWE-862
- NVD status
- Analyzed
- Published
- 2026-01-06
CVE-2026-0628 at NVD
2 known exploits for CVE-2026-0628
Proof-of-concept code and exploit modules indexed by Sploitus