Junglewise Threat Intelligence

CVE-2026-13982: Google Chrome UI spoofing in Passwords

CVE-2026-13982 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's password management interface could allow a malicious website to trick users by spoofing parts of the browser's user interface. If an attacker has already partially compromised the browser's rendering process, they could display deceptive information to the user, potentially leading to confusion or further social engineering attacks. This issue is resolved in Chrome version 150.0.7871.47 and later.

Technical details

A UI spoofing vulnerability exists in the Password management component of Google Chrome. The flaw stems from an incorrect security UI implementation that fails to properly isolate or validate interface elements when the renderer process is compromised. An attacker who has achieved remote code execution within a sandboxed renderer process can leverage a specially crafted HTML page to manipulate the browser's password-related UI. This could be used to deceive a user into performing unintended actions or believing they are interacting with a legitimate security prompt. The vulnerability is addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats