Junglewise Threat Intelligence

CVE-2026-18007: Google Chrome for Android UI spoofing in Input

CVE-2026-18007 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to spoof the browser's user interface. This means an attacker could trick a user into thinking they are interacting with a legitimate website or browser element when they are not. Such an exploit could be used to facilitate phishing attacks or deceive users into performing unintended actions.

Technical details

A UI spoofing vulnerability exists in the Input component of Google Chrome for Android. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when processing specific HTML content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent the browser's user interface, potentially leading to user confusion or credential theft. This issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats