Junglewise Threat Intelligence

CVE-2026-17998: Google Chrome UI spoofing in Extensions

CVE-2026-17998 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in how it displays information for browser extensions. An attacker could trick a user into installing a malicious extension that mimics legitimate browser interfaces or security warnings. This could lead to users being deceived into providing sensitive information or performing actions they did not intend to, under the impression they were interacting with a trusted part of the browser.

Technical details

A UI spoofing vulnerability exists in the Extensions component of Google Chrome due to an incorrect security UI implementation. The flaw allows a specially crafted malicious extension to misrepresent its identity or spoof browser UI elements. To exploit this, an attacker must successfully convince a user to install the malicious extension, typically through social engineering. Once installed, the extension can perform UI spoofing, potentially leading to user confusion or credential harvesting. The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats