MEDIUM

CVE-2026-12459

Google Chrome 2026-06-17 CVSS v3.1
CVSS
6.1

Description

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

A universal cross-site scripting (UXSS) vulnerability in Google Chrome's Serial API implementation allows a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page. The Serial API, which enables web pages to communicate with serial devices, has an improper input validation or context handling flaw that bypasses same-origin policy protections.

Mitigation

Update Google Chrome to version 149.0.7827.155 or later to patch the Serial API vulnerability. Users should avoid visiting untrusted websites until the browser is updated.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.18%
Probability of exploitation in next 30 days
7.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE