CVE-2012-2886: Google Chrome
Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Google V8 bindings, aka "Universal XSS (UXSS)."
Affected products
- Google Chrome: up to and including 22.0.1229.78; version 22.0.1229.0 only; version 22.0.1229.1 only; version 22.0.1229.2 only; version 22.0.1229.3 only; version 22.0.1229.4 only; …
- Opensuse Opensuse: version 12.1 only; version 12.2 only
Published 2012-09-26. Last modified 2026-06-16.