CVE-2026-7953: Insufficient validation of untrusted input in Omnibox
Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox
Other sources
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 148.0.7778.96 - Upgrade
Upgrade
Google Chrome/Chromiumto a version that resolves this vulnerability.Fixed in 148.0.7778.96 - Compensating control
If immediate update is not possible, reduce exposure to malicious network traffic targeting the Omnibox (e.g., limit access to untrusted networks or apply network filtering to block malicious traffic).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-7896
- CVE-2026-7897
- CVE-2026-7898
- CVE-2026-7899
- CVE-2026-7900
- CVE-2026-7901
- CVE-2026-7902
- CVE-2026-7903
- CVE-2026-7904
- CVE-2026-7905
- CVE-2026-7906
- CVE-2026-7907
- CVE-2026-7908
- CVE-2026-7909
- CVE-2026-7910
- CVE-2026-7911
- CVE-2026-7912
- CVE-2026-7913
- CVE-2026-7914
- CVE-2026-7915
- CVE-2026-7916
- CVE-2026-7917
- CVE-2026-7918
- CVE-2026-7919
- CVE-2026-7920
- CVE-2026-7921
- CVE-2026-7922
- CVE-2026-7923
- CVE-2026-7924
- CVE-2026-7925
- CVE-2026-7926
- CVE-2026-7927
- CVE-2026-7928
- CVE-2026-7929
- CVE-2026-7931
- CVE-2026-7932
- CVE-2026-7933
- CVE-2026-7934
- CVE-2026-7935
- CVE-2026-7937
- CVE-2026-7938
- CVE-2026-7939
- CVE-2026-7940
- CVE-2026-7941
- CVE-2026-7942
- CVE-2026-7943
- CVE-2026-7944
- CVE-2026-7945
- CVE-2026-7946
- CVE-2026-7947
- CVE-2026-7948
- CVE-2026-7949
- CVE-2026-7950
- CVE-2026-7951
- CVE-2026-7952
- CVE-2026-7954
- CVE-2026-7955
- CVE-2026-7956
- CVE-2026-7957
- CVE-2026-7958
- CVE-2026-7959
- CVE-2026-7960
- CVE-2026-7961
- CVE-2026-7962
- CVE-2026-7963
- CVE-2026-7964
- CVE-2026-7965
- CVE-2026-7966
- CVE-2026-7967
- CVE-2026-7968
- CVE-2026-7969
- CVE-2026-7970
- CVE-2026-7971
- CVE-2026-7972
- CVE-2026-7973
- CVE-2026-7974
- CVE-2026-7975
- CVE-2026-7976
- CVE-2026-7977
- CVE-2026-7978
- CVE-2026-7979
- CVE-2026-7980
- CVE-2026-7981
- CVE-2026-7982
- CVE-2026-7983
- CVE-2026-7984
- CVE-2026-7985
- CVE-2026-7986
- CVE-2026-7987
- CVE-2026-7988
- CVE-2026-7989
- CVE-2026-7990
- CVE-2026-7991
- CVE-2026-7992
- CVE-2026-7993
- CVE-2026-7994
- CVE-2026-7995
- CVE-2026-7996
- CVE-2026-7997
- CVE-2026-7998
- CVE-2026-7999
- CVE-2026-8000
- CVE-2026-8001
- CVE-2026-8002
- CVE-2026-8003
- CVE-2026-8004
- CVE-2026-8005
- CVE-2026-8006
- CVE-2026-8007
- CVE-2026-8008
- CVE-2026-8009
- CVE-2026-8010
- CVE-2026-8011
- CVE-2026-8012
- CVE-2026-8013
- CVE-2026-8014
- CVE-2026-8015
- CVE-2026-8016
- CVE-2026-8017
- CVE-2026-8018
- CVE-2026-8019
- CVE-2026-8020
- CVE-2026-8021
- CVE-2026-8022
Frequently Asked Questions
What is the severity of CVE-2026-7953?
CVE-2026-7953 has a medium severity rating of 6.1 based on CVSS 3.1.
How do I fix CVE-2026-7953?
To fix CVE-2026-7953, update Google Chrome or Microsoft Edge to version 148.0.7778.96 or later.
What type of attack does CVE-2026-7953 allow?
CVE-2026-7953 allows a remote attacker to inject arbitrary scripts or HTML through insufficient validation of untrusted input.
Which software is affected by CVE-2026-7953?
CVE-2026-7953 affects Google Chrome and Microsoft Edge (Chromium-based) prior to version 148.0.7778.96.
What is the primary vulnerability in CVE-2026-7953?
The primary vulnerability in CVE-2026-7953 is insufficient validation of untrusted input in Omnibox.