What is CVE-2026-16415?
CVE-2026-16415 is an insufficient validation of untrusted input vulnerability in Extensions in Google Chrome prior to version 150.0.7871.182, allowing a remote attacker to spoof the Omnibox (URL bar) contents via a crafted HTML page. Users should update their browser to the specified version or later immediately.
Azərbaycanca: CVE-2026-16415, Google Chrome-un 150.0.7871.182-dən əvvəlki versiyalarında Extensions komponentində kifayət qədər yoxlanılmamış etibarsız giriş zəifliyidir. Uzaqdan olan hücumçu xüsusi hazırlanmış HTML səhifəsi vasitəsilə Omnibox (URL bar) məzmununu saxtalaşdıra bilər. İstifadəçilər dərhal brauzerlərini göstərilən versiyaya və ya daha yenisinə yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: Google
FAQ2
What component of Google Chrome is affected by CVE-2026-16415?
This vulnerability affects the Extensions component of Google Chrome.
What can an attacker achieve by exploiting CVE-2026-16415?
A remote attacker can spoof the Omnibox (URL bar) contents via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.