CVE-2026-0628: Google Chrome

High severity, CVSS 8.8. EPSS: 20.9% chance of exploitation in the next 30 days.

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

Affected products

  • Google Chrome: before 143.0.7499.192 (fixed in 143.0.7499.192)

Published 2026-01-07. Last modified 2026-06-17.