Junglewise Threat Intelligence

CVE-2026-13939: Google Chrome for Android UI spoofing in WebShare

CVE-2026-13939 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the WebShare component could allow a malicious website to trick users by spoofing parts of the browser's user interface. This could lead to users being misled into performing unintended actions or sharing data with untrusted sources.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebShare component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to manipulate the browser's user interface. By enticing a user to visit a specially crafted HTML page, the attacker can perform UI spoofing. This vulnerability is mitigated by the requirement of a prior renderer compromise and user interaction. The issue is addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats