Junglewise Threat Intelligence

CVE-2026-13994: Google Chrome for Android UI spoofing in Credential Management

CVE-2026-13994 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a mobile web browser used to access the internet. A vulnerability in its credential management system could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate browser prompts.

Technical details

An inappropriate implementation in the Credential Management component of Google Chrome on Android allowed a remote attacker to perform UI spoofing. By enticing a user to visit a specially crafted HTML page, an attacker could manipulate the browser's user interface elements. This vulnerability is classified as Medium severity by Chromium and affects versions prior to 150.0.7871.47. The flaw likely stems from insufficient validation or logic errors in how credential-related prompts are rendered or managed on mobile devices. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats