Junglewise Threat Intelligence

CVE-2026-13996: Google Chrome UI spoofing in Permissions

CVE-2026-13996 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's permission handling could allow a malicious website to trick users by spoofing parts of the browser's user interface. An attacker could use a specially crafted webpage to display misleading information or prompts, potentially leading a user to grant unintended permissions or perform actions they did not intend. This issue primarily impacts the integrity of the user's browsing experience and their ability to make informed security decisions.

Technical details

A UI spoofing vulnerability exists in the Permissions component of Google Chrome due to an inappropriate implementation. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent or overlap browser UI elements, potentially tricking the user into granting sensitive permissions. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. Chromium developers classified this with a Medium severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats