Cross-site scripting in Google Chromium - CVE-2026-79234
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject unintended content.
The vulnerability exists due to improper neutralization of input during web page generation in the CSS handling component when rendering crafted web content. A remote attacker can cause the browser to process crafted CSS content to inject unintended content.
User interaction is required to load or open crafted web content.
Affected software
Google Chrome
How to mitigate CVE-2026-79234
Google Chrome - addressed in versions 151.0.7922.175, 152.0.7977.64