SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15128

MEDIUM · CVSS 6.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in the Forms implementation of Google Chrome prior to version 150.0.7871.115 allows remote attackers to inject arbitrary scripts or HTML through specially crafted HTML pages, leading to potential user data exposure or session hijacking (UXSS). Organizations using affected versions of Chrome should prioritize patching to mitigate the risk of exploitation. This issue is particularly relevant for environments handling sensitive user data or requiring secure web interactions.

CVE
CVE-2026-15128
Severity
MEDIUM
CVSS
6.1
EPSS
0.14%
Chrome

Original NVD Description

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)