Junglewise Threat Intelligence

CVE-2026-13955: Google Chrome UI spoofing in CustomTabs

CVE-2026-13955 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains a security flaw in its CustomTabs feature, which allows apps to open web content within their own interface. A local attacker could use a specially crafted file to trick the browser into displaying misleading information or spoofing the user interface. This could be used to deceive users into performing unintended actions or trusting a malicious site.

Technical details

An improper input validation vulnerability (CWE-20) exists in the CustomTabs component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when processing files locally. A local attacker can exploit this by providing a malicious file that, when opened, causes the browser to display a spoofed user interface. This UI spoofing can be used to misrepresent the origin or content of a page to the user. The vulnerability is addressed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats