Junglewise Threat Intelligence

CVE-2026-13986: Google ChromeOS UI spoofing in Media UI

CVE-2026-13986 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A vulnerability in the Media user interface of Google Chrome on ChromeOS could allow a malicious website to trick users. By convincing a user to perform specific interactions, an attacker can spoof parts of the browser's interface. This could be used to mislead users about the source or nature of media content they are viewing, potentially leading to further social engineering attacks.

Technical details

A UI spoofing vulnerability exists in the Media UI component of Google Chrome on ChromeOS prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements during specific user gestures. A remote attacker can exploit this by hosting a specially crafted HTML page and tricking a user into performing specific UI interactions. Successful exploitation allows the attacker to misrepresent interface elements, which can be leveraged for phishing or social engineering. The issue is addressed in ChromeOS version 150.0.7871.47.

Affected products

  • Google ChromeOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats