Skip to main content
CVE Vulnerability Database

CVE-2026-8012: Google Chrome MHTML UXSS Vulnerability

CVE-2026-8012 is a universal cross-site scripting flaw in Google Chrome's MHTML implementation that enables script injection via compromised renderer processes. This article covers technical details, affected versions, and patches.

Published:

CVE-2026-8012 Overview

CVE-2026-8012 is a Universal Cross-Site Scripting (UXSS) vulnerability in the MHTML (MIME HTML) implementation of Google Chrome prior to version 148.0.7778.96. The flaw allows a remote attacker who has already compromised the renderer process to inject arbitrary scripts or HTML into pages through a crafted HTML document. The issue is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation. Google rated the underlying Chromium severity as Low, while the NVD assigned a medium CVSS score reflecting the user interaction requirement and limited scope of impact.

Critical Impact

An attacker controlling a compromised renderer can leverage MHTML processing to bypass same-origin protections and execute scripts in the context of arbitrary origins, enabling session theft or content manipulation.

Affected Products

  • Google Chrome versions prior to 148.0.7778.96
  • Chromium-based browsers using vulnerable MHTML handling logic
  • Desktop Chrome Stable channel builds before the May 2026 update

Discovery Timeline

  • 2026-05-06 - CVE-2026-8012 published to NVD
  • 2026-05-06 - Last updated in NVD database

Technical Details for CVE-2026-8012

Vulnerability Analysis

The vulnerability resides in Chrome's MHTML (MIME HTML) parsing and rendering pipeline. MHTML is a web page archive format that combines HTML, images, and other resources into a single MIME-encoded file. Chrome's implementation fails to properly enforce origin boundaries when processing crafted MHTML content delivered through a compromised renderer process.

Because the flaw requires a renderer that an attacker already controls, exploitation is typically chained with a separate sandbox-bound bug or a memory corruption primitive. Once chained, the attacker can inject HTML or JavaScript that executes in the security context of an unrelated origin, defeating the same-origin policy.

The impact is classified as Universal Cross-Site Scripting (UXSS), a class of browser flaw more dangerous than reflected or stored XSS because it does not depend on a vulnerable target site.

Root Cause

The root cause is inappropriate implementation of origin checks during MHTML resource loading. Chrome's MHTML handler does not adequately validate or isolate the origin attribution of inline content, allowing a renderer to influence how parsed parts are associated with a given security principal. This violates the input neutralization requirements described by CWE-79.

Attack Vector

Exploitation requires a two-stage scenario. First, the attacker must compromise the Chrome renderer process, typically via a separate vulnerability. Second, the attacker delivers a crafted HTML page that triggers the MHTML logic flaw, causing scripts or HTML to be injected into a target origin. The user must visit the malicious page, satisfying the user interaction requirement.

The vulnerability mechanism is described in the Google Chrome Stable Update advisory and the Chromium Issue Tracker entry. No public proof-of-concept code is currently available.

Detection Methods for CVE-2026-8012

Indicators of Compromise

  • Chrome browser processes loading .mhtml or multipart/related content from untrusted external sources
  • Unexpected child renderer processes spawning under chrome.exe shortly after navigation to attacker-controlled pages
  • Outbound connections from browser sessions to credential collection or session exfiltration endpoints following MHTML rendering

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any build below 148.0.7778.96 for remediation
  • Inspect web proxy logs for Content-Type: multipart/related or message/rfc822 responses from non-corporate origins
  • Correlate browser crash telemetry with subsequent anomalous network activity to detect renderer compromise chains

Monitoring Recommendations

  • Enable centralized Chrome browser version reporting through enterprise management policies
  • Track endpoint process telemetry for browser child processes performing unusual cross-origin requests
  • Alert on download events involving MHTML archive formats from external email or web sources

How to Mitigate CVE-2026-8012

Immediate Actions Required

  • Update Google Chrome to version 148.0.7778.96 or later on all managed endpoints
  • Force-restart browser sessions to ensure the patched binary is loaded into memory
  • Audit Chromium-based browsers (Edge, Brave, Opera, Vivaldi) and apply vendor updates that incorporate the upstream fix

Patch Information

Google released the fix in the Chrome Stable channel update documented in the Chrome Releases blog. Administrators should deploy Chrome 148.0.7778.96 or higher. Chromium downstream projects should pull the corresponding upstream commits referenced in the Chromium Issue Tracker.

Workarounds

  • Disable MHTML save and load support through enterprise policy where the format is not required for business workflows
  • Restrict opening of .mhtml and .mht files via group policy or endpoint application control
  • Enforce strict site isolation and Enhanced Safe Browsing settings to reduce the success rate of renderer compromise chains
bash
# Configuration example: enforce minimum Chrome version via Group Policy (Windows)
# Registry path: HKLM\Software\Policies\Google\Chrome
reg add "HKLM\Software\Policies\Google\Chrome" /v SavingBrowserHistoryDisabled /t REG_DWORD /d 0 /f
reg add "HKLM\Software\Policies\Google\Chrome" /v IsolateOrigins /t REG_SZ /d "*" /f
reg add "HKLM\Software\Policies\Google\Chrome" /v SitePerProcess /t REG_DWORD /d 1 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.