CVE-2026-0628

Description

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.025

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2026-0628 are fixed in Google Chrome (143.0.7499.192,143.0.7499.193)Windows
Vulnerabilities CVE-2026-0628 are fixed in Google Chrome (x64) (143.0.7499.192,143.0.7499.193)Windows
Vulnerabilities CVE-2026-0628 are fixed in Google Chrome (User Based) 143.0.7499.193Windows
Vulnerabilities CVE-2026-0628 are fixed in Microsoft Edge for chromium business (143.0.3650.139) (x86)Windows
Vulnerabilities CVE-2026-0628 are fixed in Microsoft Edge for chromium business (143.0.3650.139) (x64)Windows
Vulnerabilities CVE-2026-0628 are fixed in Google Chrome for Mac 143.0.7499.193Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-613193Google Chrome for Mac (143.0.7499.192, 143.0.7499.193)
PATCH-354768Google Chrome (143.0.7499.192,143.0.7499.193)
PATCH-354769Google Chrome (x64) (143.0.7499.192,143.0.7499.193)
PATCH-43198Microsoft Edge for chromium business (143.0.3650.139) (x86)
PATCH-43199Microsoft Edge for chromium business (143.0.3650.139) (x64)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234