CVE-2026-66146: XSS
Published Aug 11, 2026
·Updated
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
Affected Software
1 affected component
Google GMS<=9.5.1
Event History
Aug 11, 2026
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66146?
The severity of CVE-2026-66146 is rated at risk 34.
2
How do I fix CVE-2026-66146?
To fix CVE-2026-66146, update Google GMS to version 9.5.2 or later.
3
What types of attacks are possible with CVE-2026-66146?
CVE-2026-66146 allows remote attackers to execute JavaScript in a user's browser through multiple XSS vulnerabilities.
4
Which versions of Google GMS are affected by CVE-2026-66146?
Google GMS versions 9.5.1 (Build 9510.1044) and earlier are affected by CVE-2026-66146.
5
Who is the vendor for CVE-2026-66146?
The vendor for CVE-2026-66146 is Google, for their Google GMS software.