CVE-2026-0628Missing Authorization in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.0%
top 93.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMar 2

Description

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome143.0.7499.192143.0.7499.192
NVDgoogle/chrome< 143.0.7499.192
Debianchromium/chromium< 143.0.7499.192-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2026-0628: Insufficient policy enforcement in WebView tag in Google Chrome prior to 1432026-01-07
GHSA
GHSA-rw66-g8v8-wcwh: Insufficient policy enforcement in WebView tag in Google Chrome prior to 1432026-01-07
CVEList
CVE-2026-0628: Insufficient policy enforcement in WebView tag in Google Chrome prior to 1432026-01-06

📋Vendor Advisories

3
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2026-06282026-01-16
Microsoft
Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag2026-01-13
Debian
CVE-2026-0628: chromium - Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7...2026

🕵️Threat Intelligence

3
Unit42
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel2026-03-02
Unit42
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel2026-03-02
Wiz
CVE-2026-0628 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0628 — Missing Authorization in Google Chrome | cvebase