
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13957 is an incorrect security UI vulnerability in the Extensions component of Google Chrome that enables Universal Cross-Site Scripting (UXSS). An attacker who convinces a user to install a malicious browser extension can inject arbitrary scripts or HTML into web pages via a crafted HTML page. The vulnerability affects all Google Chrome versions prior to 150.0.7871.47 on Windows, Mac, and Linux. It was reported internally by Google on 2026-05-15 and publicly disclosed on 2026-06-30 as part of the Chrome 150 stable channel release. It carries a CVSS v3.1 base score of 4.2 (Medium) (Chrome Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), manifesting as an incorrect security UI in Chrome's Extensions subsystem (Chromium issue #513553557). The flaw allows a malicious extension to bypass the browser's normal same-origin policy enforcement, enabling UXSS — script injection that executes in the context of arbitrary websites the user visits, not just the extension's own origin. Exploitation requires the attacker to first socially engineer the victim into installing a crafted malicious extension, after which a specially constructed HTML page triggers the script injection. No public technical write-up or proof-of-concept code has been identified (Chrome Advisory).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript or HTML in the context of any website the victim visits, effectively bypassing the same-origin policy. This can lead to theft of session cookies, credentials, and other sensitive data from any web origin, as well as unauthorized actions performed on behalf of the user across websites. Confidentiality and integrity are both partially impacted; availability is not directly affected. The UXSS nature of the vulnerability means the blast radius extends to all websites visited by the compromised user, not just a single target (Chrome Advisory).
chrome://extensions/); extensions with broad host permissions (<all_urls>) that were not explicitly installed by the user.Update Google Chrome to version 150.0.7871.47 (Windows/Mac) or 150.0.7871.46 (Linux) or later, which contains the fix for this vulnerability. Users should audit installed extensions and remove any that are unfamiliar or from untrusted sources. As a workaround, organizations can use Chrome enterprise policies (e.g., ExtensionInstallBlocklist, ExtensionInstallAllowlist) to restrict which extensions users are permitted to install. Users should only install extensions from the official Chrome Web Store and carefully review requested permissions before installation (Chrome Advisory).
The CIS (Center for Internet Security) published an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-13957, could allow for arbitrary code execution, recommending prompt patching. The vulnerability was also picked up by security scanner vendors including Tenable (Nessus plugins 325118, 325675) and Qualys (detection IDs 387756, 387805), indicating broad coverage in enterprise vulnerability management tooling. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."