CVE-2026-0628 is a high-severity vulnerability in Google Chrome prior to version 143.0.7499.192, stemming from insufficient policy enforcement within the WebView tag. This flaw allows a malicious Chrome extension, if installed by a user, to inject scripts or HTML into privileged pages. The vulnerability carries a CVSS score of 8.8 (HIGH), indicating a critical risk with high impacts on confidentiality, integrity, and availability, requiring user interaction but no prior authentication. The attack vector is network-based with low complexity, as an attacker needs to convince a user to install a malicious extension. The potential impact is significant, enabling an attacker to gain control over privileged browser functions, as highlighted by reports of extensions potentially hijacking Gemini's camera, microphone, and file access. Currently, there is no evidence of active exploitation (KEV: No), and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered substantial community attention with over 10 mentions and 8 media articles, indicating a high level of concern and discussion within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 143.0.7499.192, < 143.0.7499.192CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 143.0.7499.192CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.