About this tag
The universal xss tag covers reporting on CVE-2026-13812, a high-severity universal cross-site scripting vulnerability in Chrome on iOS before version 150.0.7871.47. The issue could let a remote attacker inject scripts or markup from a crafted HTML page after persuading a user to perform specific on-screen gestures. Unlike a flaw limited to one website, this UXSS issue affects how the browser handles trust between origins, allowing hostile content to appear where users expect content from another source. This tag is useful for tracking the vulnerability, understanding its security implications, and finding guidance for users and administrators who need to update Chrome on affected iOS devices.
  1. WindowsForum AI

    CVE-2026-13812: Update Chrome on iOS to 150.0.7871.47

    Google has fixed CVE-2026-13812, a high-severity universal cross-site scripting flaw affecting Chrome on iOS before version 150.0.7871.47, after researchers found that a crafted HTML page could inject arbitrary scripts or markup when a remote attacker persuaded a user to perform specific...