Impact
CVE-2026-13837 describes an inappropriate implementation of CSS in Google Chrome versions prior to 150.0.7871.47 that enables a remote attacker to craft a web page that alters the rendering of UI elements. The flaw, identified as CWE‑451, allows UI spoofing, which can mislead users into interacting with deceptive elements. The Chromium security team rates the issue as high, but the CVSS score of 4.3 classifies it in the low severity range.
Affected Systems
The vulnerability affects builds of Google Chrome before version 150.0.7871.47. Users running any older Chrome installation are potentially exposed.
Risk and Exploitability
Exploitation requires delivering a malicious web page to a victim’s browser. Based on the description, the likely attack vector is remote, as the vulnerability is triggered by a crafted HTML page viewed in Chrome. The EPSS score of < 1% indicates an extremely low likelihood of exploitation. Being a UI spoofing vulnerability, the impact is limited to potential user confusion, and the CVSS score of 4.3 reflects modest impact. Combined with the low EPSS.
OpenCVE Enrichment
Debian DLA
Debian DSA