All CVEs
Vulnerability intelligence

CVE-2026-0628

Google Chrome

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVSS Score
Unrated
EPSS — Exploit Probability
6.6%
Riskier than 94% of all CVEs · checked 2026-09-16
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

7 articles across 6 outlets · first covered Mar 2, 2026 · latest Sep 16, 2026

Coverage timeline

Related CVEs — Google