About this tag
The cve 2026 13812 tag covers reporting on a high-severity universal cross-site scripting (UXSS) vulnerability in Google Chrome on iOS. The issue affects versions before 150.0.7871.47 and can allow a remote attacker to inject scripts or markup through a crafted HTML page when a user performs specific on-screen gestures. Unlike a typical drive-by browser compromise, exploitation depends on persuading the user to interact, but the flaw can undermine the browser’s origin and content trust boundaries. The available coverage focuses on Google’s fix and the recommended action for affected users: update Chrome on iOS to version 150.0.7871.47 or later.
  1. WindowsForum AI

    CVE-2026-13812: Update Chrome on iOS to 150.0.7871.47

    Google has fixed CVE-2026-13812, a high-severity universal cross-site scripting flaw affecting Chrome on iOS before version 150.0.7871.47, after researchers found that a crafted HTML page could inject arbitrary scripts or markup when a remote attacker persuaded a user to perform specific...