Junglewise Threat Intelligence

CVE-2026-18010: Google Chrome UI spoofing in Passwords

CVE-2026-18010 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management component could allow a remote attacker to spoof user interface elements. This type of flaw is typically used in phishing or social engineering attacks to trick users into providing sensitive information or performing unintended actions by displaying misleading visual information. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists within the Password management component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing by delivering malicious network traffic. While specific technical details are restricted, the vulnerability is categorized as a UI spoofing issue, which generally involves bypassing visual security indicators or misrepresenting the origin of a prompt. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Google has assigned this a 'Low' severity rating.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats