Junglewise Threat Intelligence

CVE-2026-13997: Google Chrome for Android UI spoofing in Extensions

CVE-2026-13997 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to trick users into performing unintended actions. By using specially crafted web pages and convincing a user to interact with specific parts of the screen, an attacker could misrepresent or hide security warnings related to browser extensions. This could lead to a user unknowingly installing or interacting with a malicious extension, potentially compromising their browsing privacy.

Technical details

A UI spoofing vulnerability exists in the Extensions component of Google Chrome for Android prior to version 150.0.7871.47. The flaw stems from incorrect security UI handling, which can be exploited by a remote attacker who convinces a user to engage in specific UI gestures on a crafted HTML page. Successful exploitation allows the attacker to overlap or misrepresent security-critical interface elements. This is categorized by Chromium as Medium severity. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats