CVE-2026-3063Google Chrome vulnerability

9 documents9 sources
Severity
5.4MEDIUMNVD
EPSS
0.0%
top 99.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateFeb 24

Description

Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages3 packages

CVEListV5google/chrome145.0.7632.116145.0.7632.116
NVDgoogle/chrome< 145.0.7632.116+1
Debianchromium/chromium< 145.0.7632.116-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-33jq-j95r-2gpj: Inappropriate implementation in DevTools in Google Chrome prior to 1452026-02-24
CVEList
CVE-2026-3063: Inappropriate implementation in DevTools in Google Chrome prior to 1452026-02-23
OSV
CVE-2026-3063: Inappropriate implementation in DevTools in Google Chrome prior to 1452026-02-23

📋Vendor Advisories

4
Red Hat
chromium-browser: Inappropriate implementation in DevTools2026-02-23
Chrome
Stable Channel Update for Desktop: CVE-2026-30612026-02-23
Microsoft
Chromium: CVE-2026-3063 Inappropriate implementation in DevTools2026-02-10
Debian
CVE-2026-3063: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.11...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-3063 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-3063 — Google Chrome vulnerability | cvebase