Junglewise Threat Intelligence

CVE-2026-17970: Google Chrome UI spoofing in Passwords

CVE-2026-17970 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password management component contained a flaw that could allow a malicious actor on a local or privileged network to manipulate the browser's user interface. By sending specially crafted network traffic, an attacker could trick users into performing unintended actions or disclosing information through spoofed visual elements. This vulnerability primarily impacts the integrity of the user's browsing experience and could be used in phishing-style attacks.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in the Passwords component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which allows an attacker positioned in a privileged network location (such as a Man-in-the-Middle) to perform UI spoofing via malicious network traffic. This could lead to the presentation of deceptive browser interfaces to the user. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats