SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15127

MEDIUM · CVSS 6.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in the WebGL implementation of Google Chrome prior to version 150.0.7871.115 allows remote attackers to inject arbitrary scripts or HTML through specially crafted HTML pages, leading to potential user experience security issues (UXSS). This could enable attackers to manipulate web content and compromise user data. Organizations using affected versions of Chrome should prioritize updates to mitigate this risk.

CVE
CVE-2026-15127
Severity
MEDIUM
CVSS
6.1
EPSS
0.14%
Chrome

Original NVD Description

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)