Junglewise Threat Intelligence

CVE-2026-13998: Google Chrome UI spoofing in File Input on macOS

CVE-2026-13998 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security interface issue in Google Chrome on macOS could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with specific parts of a webpage, an attacker could spoof the browser's user interface to hide or misrepresent file upload activities. This could lead to a user inadvertently providing access to files or being misled about the security state of their browser session.

Technical details

A UI spoofing vulnerability exists in the File Input component of Google Chrome on macOS. The flaw stems from an incorrect security UI implementation that fails to properly handle specific user gestures on a crafted HTML page. A remote attacker can exploit this by tricking a user into performing specific UI interactions, allowing the attacker to overlap or misrepresent browser interface elements. This can be used to deceive users about the nature of file inputs or other security-sensitive UI components. The issue is resolved in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats