Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17878

CVE-2026-17878: Google Chrome CSS UXSS Vulnerability

CVE-2026-17878 is a universal cross-site scripting flaw in Google Chrome's CSS implementation that enables attackers to inject malicious scripts via crafted HTML pages. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-17878 Overview

CVE-2026-17878 is a Universal Cross-Site Scripting (UXSS) vulnerability in Google Chrome caused by an inappropriate implementation in the browser's CSS engine. A remote attacker can inject arbitrary scripts or HTML into rendered pages by delivering a crafted HTML document to a target user. The flaw affects Google Chrome versions prior to 151.0.7922.72 on the desktop stable channel. Chromium rates the security severity as Medium. Exploitation requires the victim to visit or load attacker-controlled content, after which script execution occurs within the origin context of targeted pages.

Critical Impact

Successful exploitation enables Universal Cross-Site Scripting, letting attackers bypass same-origin policy and run arbitrary scripts or HTML in the context of other web origins.

Affected Products

  • Google Chrome desktop versions prior to 151.0.7922.72
  • Chromium-based browsers sharing the affected CSS implementation
  • Downstream distributions bundling vulnerable Chrome builds

Discovery Timeline

  • 2026-07-30 - CVE-2026-17878 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17878

Vulnerability Analysis

The vulnerability resides in Chrome's CSS implementation. An inappropriate implementation permits attacker-controlled CSS behavior to influence how HTML or script content is rendered or evaluated across origin boundaries. This class of flaw is categorized as Universal Cross-Site Scripting because the resulting script execution is not confined to a single attacker-controlled origin.

UXSS conditions in browsers typically arise when the rendering pipeline treats untrusted content with elevated privileges or misapplies origin checks during style, layout, or resource loading. The public advisory does not disclose implementation-level details, and the Chromium issue tracker entry remains restricted. Google follows a policy of limiting technical disclosure until the majority of users have applied the fix.

Root Cause

The root cause is described by the vendor as an inappropriate implementation within the CSS subsystem. This indicates a logic or design flaw rather than a memory-safety bug. The defective behavior allows a crafted HTML page to influence content interpretation in a manner that permits script or HTML injection across contexts.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker hosts a crafted HTML page and induces the victim to load it, for example through phishing, malvertising, or a compromised website. Once loaded, the malicious CSS-driven payload triggers cross-context script or HTML injection without further user action.

No public proof-of-concept is available, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. See the Google Chrome Update Announcement and the Chromium Issue Tracker Entry for vendor references.

Detection Methods for CVE-2026-17878

Indicators of Compromise

  • Chrome desktop clients reporting a version string earlier than 151.0.7922.72 in enterprise inventory or User-Agent telemetry.
  • Browser navigation events to unfamiliar domains immediately followed by unexpected script execution or DOM modifications in unrelated origins.
  • Outbound requests from browser processes to attacker-controlled infrastructure shortly after loading an HTML document containing anomalous CSS constructs.

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any host below the fixed build 151.0.7922.72.
  • Correlate web proxy logs with endpoint process telemetry to identify Chrome renderer activity following visits to newly registered or low-reputation domains.
  • Alert on HTML responses that contain unusual CSS patterns combined with <script> or event-handler payloads targeting third-party origins.

Monitoring Recommendations

  • Ingest browser version telemetry and web gateway logs into a centralized analytics platform for continuous version-drift and URL-reputation monitoring.
  • Monitor for phishing campaigns delivering links to crafted HTML pages, particularly those bypassing standard email filtering.
  • Track Chrome update compliance rates and generate exceptions for endpoints that fail to apply the stable channel update within the enterprise patch window.

How to Mitigate CVE-2026-17878

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all desktop platforms.
  • Restart Chrome after the update to ensure the patched binary is loaded into all renderer and browser processes.
  • Verify Chromium-based browsers in the environment have absorbed the upstream fix and update them accordingly.

Patch Information

Google released the fix in the stable channel update announced at the Google Chrome Update Announcement. The patched build is 151.0.7922.72. Enterprise administrators should deploy the update through Chrome Browser Cloud Management, Group Policy, or their standard software distribution tooling. Tracking details are available in the Chromium Issue Tracker Entry.

Workarounds

  • Enforce Chrome auto-update policies so endpoints receive stable channel releases without user intervention.
  • Restrict browsing to trusted sites through web proxy allowlists until patch compliance is confirmed across the fleet.
  • Enable enterprise phishing and malware protection features in Chrome and upstream email gateways to reduce delivery of crafted HTML pages.
bash
# Configuration example: verify installed Chrome version on Linux/macOS/Windows
# Linux
google-chrome --version

# macOS
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --version

# Windows (PowerShell)
(Get-Item "C:\Program Files\Google\Chrome\Application\chrome.exe").VersionInfo.ProductVersion

# Expected output: 151.0.7922.72 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.