Junglewise Threat Intelligence

CVE-2026-13979: Google Chrome UI spoofing in Paint

CVE-2026-13979 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's rendering engine could allow a malicious website to misrepresent or 'spoof' parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by making a malicious page appear as a legitimate part of the browser or a different website. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in the Paint component of Google Chrome. The flaw stems from an inappropriate implementation that fails to correctly isolate or render UI elements when processing specific HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted website. Successful exploitation allows the attacker to spoof the browser's user interface, potentially leading to phishing or other social engineering attacks. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats