Junglewise Threat Intelligence

CVE-2026-13985: Google Chrome UI spoofing in MediaCapture

CVE-2026-13985 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its MediaCapture component could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This could be used to facilitate phishing or other social engineering attacks by making malicious content appear as legitimate browser prompts.

Technical details

A UI spoofing vulnerability exists in the MediaCapture component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements during media capture operations. To exploit this, a remote attacker must first compromise the browser's renderer process. Once achieved, the attacker can use a specially crafted HTML page to manipulate the user interface, potentially misleading the user into granting permissions or interacting with malicious elements. The issue is resolved in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats