Junglewise Threat Intelligence

CVE-2026-10004: Google Chrome UI spoofing in Passwords

CVE-2026-10004 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management component could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate browser prompts. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Passwords component of Google Chrome. A remote attacker can exploit this by inducing a user to visit a specially crafted HTML page. The lack of sufficient validation allows the attacker to manipulate or spoof user interface elements related to password management. This could lead to phishing attacks or unauthorized user actions within the browser context. The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published

References

Related threats