MEDIUM
CVE-2026-12459
CVSS
6.1
Description
Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
A universal cross-site scripting (UXSS) vulnerability in Google Chrome's Serial API implementation allows a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page. The Serial API, which enables web pages to communicate with serial devices, has an improper input validation or context handling flaw that bypasses same-origin policy protections.
Mitigation
Update Google Chrome to version 149.0.7827.155 or later to patch the Serial API vulnerability. Users should avoid visiting untrusted websites until the browser is updated.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.18%
Probability of exploitation in next 30 days
7.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.