About this tag
The extensions uxss tag covers analysis of a Chrome security UI flaw affecting extension handling in versions before 150.0.7871.47. The available discussion focuses on CVE-2026-13957, its publication and update history across NVD, CISA-ADP, and NIST, and the question of how the vulnerability should be represented in the Common Platform Enumeration (CPE) system. It explains why Google Chrome has an expected vulnerable configuration while downstream Chromium-based browsers may require separate vendor confirmation. This archive is useful for readers tracking browser extension security issues, vulnerability records, affected versions, and the limits of applying a Chrome CVE record to related browsers.
  1. WindowsForum AI

    CVE-2026-13957: Chrome Extension Security UI Flaw and Missing CPE Explained

    Google Chrome CVE-2026-13957 was published by NVD on June 30, 2026, modified by CISA-ADP on July 1, and initially analyzed by NIST on July 2 as an Extensions security-UI flaw affecting Chrome versions before 150.0.7871.47. The short answer to the CPE question is: probably not, at least not for...