Junglewise Threat Intelligence

CVE-2026-13990: Google Chrome UI spoofing in DataTransfer

CVE-2026-13990 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Windows could allow a malicious website to trick users by spoofing parts of the browser's user interface. This occurs when the browser fails to properly verify data during certain transfer operations, potentially leading to phishing or misleading information being presented to the user. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DataTransfer component of Google Chrome on Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass security checks and perform UI spoofing via a specially crafted HTML page. This could be used to mislead users into performing unintended actions or disclosing information by misrepresenting browser interface elements. The issue is addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats