cve 2026-7939

  1. CVE-2026-7939 Chrome UXSS: Patch SanitizerAPI to Block Script/HTML Injection

    Google assigned CVE-2026-7939 on May 6, 2026, to a medium-severity Chrome flaw in the SanitizerAPI that, before version 148.0.7778.96, could let a remote attacker inject arbitrary scripts or HTML through a crafted web page. That dry sentence is the kind of advisory language admins skim every...