Mozilla introduced setHTML in Firefox 148 as a safer alternative to innerHTML, using built-in HTML sanitization to reduce cross-site scripting (XSS) exposure when applications insert untrusted markup. The change aims to give developers a browser-native mechanism that avoids unsafe parsing and rendering patterns associated with direct HTML injection.
Researchers also identified two XSS bypasses in Chrome 146's Sanitizer API implementation. One used SVG animation and the malformed namespaced attribute xlink:href:x to evade an attribute-blocking check; another allowed an invalid javascript: URL that GET-form URL rewriting converted into executable JavaScript. Chrome remediated both flaws in version 147, released April 7, 2026; organizations should ensure managed Chrome deployments are updated and treat browser sanitization APIs as defense-in-depth rather than a substitute for contextual output encoding and input controls.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Chrome 147 was released with fixes for both Sanitizer API XSS bypasses: the malformed SVG `xlink:href` animation bypass and the invalid JavaScript form-action URL bypass.
A patch to the `ProtocolIsJavaScript` handling landed to address a second Sanitizer API bypass involving invalid JavaScript URLs that could become executable after GET-form URL rewriting.
Chrome patched the SVG animation bypass by using the SVG attribute parser instead of a direct string comparison when filtering animation attributes.
A bypass affecting Chrome 146's Sanitizer API was reported. It used an SVG animation element with a malformed `attributeName="xlink:href:x"` value to evade filtering and animate an SVG link to a `javascript:` URL.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.