Junglewise Threat Intelligence

CVE-2026-18009: Google Chrome UI spoofing in Passwords

CVE-2026-18009 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password management component contained a vulnerability that could allow a remote attacker to spoof parts of the browser's user interface. This type of flaw is typically used in phishing or social engineering attacks to trick users into providing sensitive information or performing unintended actions by displaying misleading visual information. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in the Passwords component of Google Chrome prior to version 151.0.7922.72. The flaw stems from improper input validation (CWE-20) of untrusted data received via network traffic. A remote attacker could exploit this by sending malicious network traffic to trigger an incorrect UI state or display, potentially misleading the user. This is categorized by Chromium as a Low severity issue. The vulnerability is addressed in the stable channel update 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats