Junglewise Threat Intelligence

CVE-2026-13942: Google Chrome UI spoofing in Video Capture on ChromeOS

CVE-2026-13942 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A vulnerability in the Video Capture component of Google Chrome on ChromeOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are interacting with a legitimate system prompt. The issue is resolved in ChromeOS version 150.0.7871.47.

Technical details

An inappropriate implementation vulnerability exists in the Video Capture component of Google Chrome on ChromeOS. By leveraging a specially crafted HTML page, a local attacker (or a malicious site visited by the user) can perform user interface (UI) spoofing. This is classified as an improper input validation issue (CWE-20) within the Chromium project. The vulnerability allows an attacker to misrepresent browser or system UI elements, potentially leading to user confusion or social engineering attacks. The issue is fixed in ChromeOS versions 150.0.7871.47 and later.

Affected products

  • Google ChromeOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats