Junglewise Threat Intelligence

CVE-2026-17792: Google Chrome UI spoofing in Credential Management

CVE-2026-17792 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its Credential Management component. This flaw could allow a remote attacker to trick users by displaying deceptive user interface elements via a specially crafted website. If successful, an attacker could potentially mislead users into performing unintended actions or disclosing sensitive information by spoofing legitimate browser prompts.

Technical details

A UI spoofing vulnerability exists in the Credential Management component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when processing specific web content. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to overlay or mimic legitimate browser UI components, potentially leading to credential theft or other social engineering attacks. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats