Junglewise Threat Intelligence

CVE-2026-17939: Google Chrome UI spoofing in Passwords

CVE-2026-17939 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password management component contained a vulnerability that could allow a remote attacker to spoof user interface elements. This could be used to trick users into performing unintended actions or revealing sensitive information by displaying deceptive prompts. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in the Passwords component of Google Chrome due to insufficient validation of untrusted input. By delivering malicious network traffic, a remote attacker can manipulate the browser's user interface elements related to password management. This could lead to deceptive prompts or overlays that mislead the user. The vulnerability is present in versions prior to 151.0.7922.72 and has been addressed in the stable channel update. The Chromium project has assigned this a 'Low' severity rating.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update fixing the issue.
  • 2026-07-30: disclosed: CVE published in the NVD dataset.

References

Related threats