Junglewise Threat Intelligence

CVE-2026-13988: Google Chrome UI spoofing in Paint

CVE-2026-13988 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a malicious website to spoof parts of the browser's user interface. By tricking a user into visiting a specially crafted webpage, an attacker could misrepresent website information or security indicators. This could be used to facilitate phishing attacks or deceive users into performing unintended actions.

Technical details

A UI spoofing vulnerability exists in the Paint component of Google Chrome. The flaw stems from an inappropriate implementation that fails to correctly isolate or render certain UI elements when processing specific HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, allowing the attacker to spoof the browser's user interface. This could lead to the misrepresentation of the origin or security state of a page. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats