Junglewise Threat Intelligence

CVE-2026-13972: Google Chrome UI spoofing in Paint

CVE-2026-13972 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a malicious website to spoof parts of the browser's user interface. By tricking a user into visiting a specially crafted webpage, an attacker could display misleading information or fake browser elements to facilitate phishing or other deceptive attacks. This issue affects the 'Paint' component, which is responsible for rendering visual elements on the screen.

Technical details

An inappropriate implementation vulnerability exists in the Paint component of Google Chrome. The flaw allows a remote attacker to perform user interface (UI) spoofing by enticing a user to visit a specially crafted HTML page. While technical details are restricted, the vulnerability likely involves incorrect handling of rendering layers or visual state, allowing web content to overlap or mimic trusted browser UI elements. This is categorized by Chromium as Medium severity. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats