CVE-2026-12463
published 2026-06-17CVE-2026-12463: Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to…
medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
0.13%
3.2th percentile
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | >= 149.0.7827.155 < 149.0.7827.155 | 149.0.7827.155 | |
| chrome_desktop | — | — |
CVSS provenance
cvelistv5v3.14.7MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 149.0.7827.115 on Linux Views cross site scripting (EUVD-2026-37548 / Nessus ID 321414)
vuldb·2026-06-19
CVE-2026-12463 [CRITICAL] Google Chrome up to 149.0.7827.115 on Linux Views cross site scripting (EUVD-2026-37548 / Nessus ID 321414)
A vulnerability classified as critical was found in Google Chrome on Linux. The impacted element is an unknown function of the component Views. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-12463. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) vi
ghsa_unreviewed·2026-06-17
CVE-2026-12463 [MEDIUM] CWE-79 Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) vi
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CVEList
CVE-2026-12463: Inappropriate implementation in Views in Google Chrome on Linux prior to 149
cvelistv5·2026-06-17·CVSS 4.7
CVE-2026-12463 [MEDIUM] CVE-2026-12463: Inappropriate implementation in Views in Google Chrome on Linux prior to 149
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Red Hat
chromium-browser: chromium-browser: Inappropriate implementation in Views
vendor_redhat·2026-06-17·CVSS 8.0
CVE-2026-12463 [HIGH] CWE-79 chromium-browser: chromium-browser: Inappropriate implementation in Views
chromium-browser: chromium-browser: Inappropriate implementation in Views
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
An inappropriate implementation flaw was found in the Views component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=518042749
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-12461
vendor_chrome·2026-06-16
CVE-2026-12461 [HIGH] Stable Channel Update for Desktop: CVE-2026-12461
Stable Channel Update for Desktop
CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google on 2026-05-29 [N/A][ 517916024 ] High CVE-2026-12462: Use after free in Media
Reported by Google on 2026-05-29 [N/A][ 518042749 ] High CVE-2026-12463: Inappropriate implementation in Views
Severity: high
No detection rules found.
No public exploits indexed.
2026-06-17
Published