Skip to content
GoogleCVE-2026-16415

Google Chrome: remote attacker could spoof the contents of the Omnibox

Medium5.4CVE-2026-16415 · Published Jul 21, 2026 · updated Jul 24, 2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 150.0.7871.182, < 150.0.7871.182150.0.7871.182
Details and references

More Google advisories

All Google
Advisory
Google Chrome: use after free
Critical9.6Jul 21
Google Chrome: integer overflow
Critical9.3Jul 21
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a...
Low3.1Jul 21
Google Chrome: buffer overflow
High8.8Jul 21
Google Chrome: out-of-bounds read
Critical9.6Jul 21
Google Chrome: type confusion
High8.8Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.