Inappropriate implementation in XML in Google Chrome...
High severity
Unreviewed
Published
Jun 5, 2026
to the GitHub Advisory Database
•
Updated Jun 5, 2026
Description
Published by the National Vulnerability Database
Jun 4, 2026
Published to the GitHub Advisory Database
Jun 5, 2026
Last updated
Jun 5, 2026
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)
References