Google and Microsoft disclosed CVE-2026-8021 on May 6–7, 2026, after Chrome 148.0.7778.96 fixed a low-severity Chromium universal cross-site scripting flaw that could let a remote attacker inject scripts or HTML if a user performed specific UI gestures on a crafted page. The bug is not the...