CVE-2026-16415 PUBLISHED

Assigner: Chrome
Reserved: 20.07.2026 Published: 21.07.2026 Updated: 21.07.2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

Product Status

Vendor Google
Product Chrome
Versions
  • affected from 150.0.7871.182 to 150.0.7871.182 (excl.)

References

Problem Types

  • Insufficient validation of untrusted input