
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3063 is an inappropriate implementation vulnerability in the DevTools component of Google Chrome that allows an attacker who convinces a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. It affects Google Chrome versions prior to 145.0.7632.116 (Linux) and 145.0.7632.116/117 (Windows/Mac), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by M. Fauzan Wijaya (Gh05t666nero) on February 17, 2026, and publicly disclosed on February 23, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 5.4 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is an inappropriate implementation in Chrome's DevTools component (CWE-358: Improperly Implemented Security Check for Standard), which fails to adequately restrict script or HTML injection into privileged browser pages when accessed through DevTools. Exploitation requires the attacker to first convince a target user to install a malicious browser extension, which can then leverage the DevTools interface to inject content into privileged pages that would normally be protected. The attack vector is network-based with required user interaction (installing the malicious extension), and no special privileges are required beyond the extension installation step. Bug details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows an attacker to inject arbitrary scripts or HTML into privileged Chrome pages, potentially enabling unauthorized access to sensitive browser data, session tokens, or credentials stored within those privileged contexts. The integrity and confidentiality impacts are assessed as low, with no direct availability impact, but the ability to execute scripts in privileged page contexts could facilitate further browser-level compromise or data exfiltration. The scope is limited to the affected browser instance and does not directly enable lateral movement to the underlying operating system (Chrome Releases).
chrome:// pages or extension background pages).devtools, debugger, or tabs permissions in the extension manifest).chrome:// privileged pages from extension background scripts.--remote-debugging-port) that were not user-initiated.Users and administrators should update Google Chrome to version 145.0.7632.116 or later (145.0.7632.116/117 on Windows/Mac, 145.0.7632.116 on Linux), released February 23, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding Microsoft security update. Enabling automatic browser updates is the most effective mitigation. As a precautionary measure, organizations should enforce extension allowlisting policies via enterprise management tools to prevent installation of unauthorized extensions (Chrome Releases, Microsoft MSRC).
The vulnerability was covered by multiple security news outlets including CyberSecurityNews, GBHackers, Forbes, PCWorld, and eSecurity Planet, all framing it as part of an emergency Chrome update addressing three high-severity flaws. Forbes noted Google's confirmation of browser danger and the urgency of the Chrome 145 update. Coverage generally emphasized the social engineering prerequisite (malicious extension installation) as a mitigating factor for real-world risk. No notable researcher commentary beyond the original reporter (M. Fauzan Wijaya / Gh05t666nero) has been publicly attributed (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."