Junglewise Threat Intelligence

CVE-2026-13966: Google Chrome UI spoofing in History

CVE-2026-13966 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, was found to have a security flaw in its History component. This vulnerability could allow a malicious website to trick users by spoofing parts of the browser's user interface. If exploited, an attacker could potentially mislead a user into performing unintended actions or believing they are on a different site than they actually are.

Technical details

A UI spoofing vulnerability exists in the History component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof elements of the browser's user interface, potentially leading to phishing or other social engineering attacks. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. The Chromium project assigned this a Medium severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published the vulnerability details.
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.

References

Related threats