Junglewise Threat Intelligence

CVE-2026-18008: Google Chrome UI spoofing in Settings

CVE-2026-18008 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Settings component could allow a remote attacker to trick users by spoofing the browser's user interface. By sending malicious network traffic, an attacker could potentially display misleading information or fake prompts within the browser's settings pages. This type of attack is typically used to deceive users into performing unintended actions or disclosing sensitive information by making malicious content appear as legitimate browser interface elements.

Technical details

A UI spoofing vulnerability exists in the Settings component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this flaw by delivering malicious network traffic to a victim's browser. If successful, the attacker can manipulate or spoof elements of the browser's internal settings user interface. This could be leveraged to conduct phishing attacks or mislead the user regarding the browser's security state. The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats