Junglewise Threat Intelligence

CVE-2026-13895: Google Chrome UI spoofing in Autofill

CVE-2026-13895 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Autofill feature could allow a remote attacker to trick users into performing unintended actions. By convincing a user to interact with a specially crafted website, an attacker can spoof parts of the browser's user interface. This could lead to users providing sensitive information to a malicious site under the impression they are interacting with a legitimate browser prompt.

Technical details

A UI spoofing vulnerability exists in the Autofill component of Google Chrome due to an inappropriate implementation of interface elements. A remote attacker can exploit this by hosting a malicious HTML page and tricking a user into performing specific UI gestures (such as clicks or keyboard interactions). Successful exploitation allows the attacker to misrepresent the browser's UI, potentially leading to credential theft or other social engineering attacks. The issue is resolved in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats