CVE-2026-2322: Inappropriate implementation in File input
Chromium: CVE-2026-2322 Heap buffer overflow in Codecs
Other sources
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2322?
The severity of CVE-2026-2322 is classified as low according to Chromium security standards.
How do I fix CVE-2026-2322?
To fix CVE-2026-2322, update Google Chrome to version 145.0.7632.45 or later.
What does CVE-2026-2322 exploit?
CVE-2026-2322 exploits inappropriate implementation in the File input feature of Google Chrome.
Who is affected by CVE-2026-2322?
Users of Google Chrome versions prior to 145.0.7632.45 are affected by CVE-2026-2322.
What type of attack is associated with CVE-2026-2322?
CVE-2026-2322 is associated with UI spoofing attacks involving crafted HTML pages.