Executive brief
Google Chrome on Android is a mobile web browser used to access the internet. A vulnerability in its credential management system could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate browser prompts.
Technical details
An inappropriate implementation in the Credential Management component of Google Chrome on Android allowed a remote attacker to perform UI spoofing. By enticing a user to visit a specially crafted HTML page, an attacker could manipulate the browser's user interface elements. This vulnerability is classified as Medium severity by Chromium and affects versions prior to 150.0.7871.47. The flaw likely stems from insufficient validation or logic errors in how credential-related prompts are rendered or managed on mobile devices. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched