Junglewise Threat Intelligence

CVE-2026-13999: Google Chrome UI spoofing in Extensions

CVE-2026-13999 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's extension system could allow a malicious extension to spoof the browser's user interface. If a user is tricked into installing a specially crafted extension, the attacker could display deceptive information or mimic legitimate browser elements to facilitate further attacks. This issue has been addressed in the latest version of the Chrome browser.

Technical details

A UI spoofing vulnerability exists in the Extensions component of Google Chrome due to insufficient validation of untrusted input. An attacker can exploit this by convincing a user to install a malicious, crafted Chrome Extension. Successful exploitation allows the extension to manipulate or spoof elements of the browser's user interface, potentially leading to user confusion or credential theft through deceptive overlays. The vulnerability is fixed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published advisory
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats