Junglewise Threat Intelligence

CVE-2026-17840: Google Chrome domain spoofing in Passwords UI

CVE-2026-17840 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's password management interface could allow a malicious website to misrepresent its identity. By tricking the browser's user interface, an attacker could perform domain spoofing, potentially leading users to believe they are interacting with a legitimate site when they are actually on a fraudulent one. This could be used to facilitate phishing attacks or unauthorized credential entry.

Technical details

An incorrect security UI implementation in the Passwords component of Google Chrome allowed a remote attacker to perform domain spoofing. The vulnerability is triggered when a user visits a specially crafted HTML page designed to manipulate how the browser displays origin or security information within the password manager interface. This flaw enables an attacker to bypass certain UI-based security indicators, potentially leading to credential theft through phishing. The issue is resolved in Google Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: CVE published to NVD

References

Related threats