Junglewise Threat Intelligence

CVE-2026-13989: Google Chrome UI spoofing in PageInfo

CVE-2026-13989 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's PageInfo component could allow a malicious website to misrepresent its identity or security status. If an attacker has already partially compromised the browser's internal rendering process, they could use this flaw to trick users into believing they are on a legitimate site or that a connection is secure when it is not. This type of 'UI spoofing' is often used in phishing attacks to steal sensitive information.

Technical details

An inappropriate implementation in the PageInfo component of Google Chrome allowed for UI spoofing. The vulnerability requires a remote attacker to have already compromised the renderer process. By leveraging this foothold, the attacker could serve a specially crafted HTML page to manipulate the browser's user interface elements that display site information. This could lead to a user being misled about the origin or security properties of the site they are visiting. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats