Description
Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw in Google Chrome’s media component on Windows allows a remote attacker who has already compromised the renderer process to spoof the browser’s UI through a crafted HTML page. The attacker can make the browser display forged interface elements that mislead users about the source of displayed information, effectively undermining the authenticity of the UI. This flaw is categorized as CWE-284.

Affected Systems

All Windows installations of Google Chrome older than version 150.0.7871.47 are affected. Specifically, any system running Chrome 150.0.7871.46 or earlier, where the media handling component has not been patched, is vulnerable to this exploitation technique.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium severity. An EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to have already gained control of the renderer process, meaning the vulnerability can only be leveraged after a prior foothold has been established. Under those conditions, the attacker can reliably spoof UI elements, but the overall risk remains moderate given the exploitation prerequisites.

Generated by OpenCVE AI on July 17, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later.
  • Configure Chrome to run renderer processes with strict isolation settings and limit external debugging interfaces.
  • Leverage browser monitoring and anomaly detection tools to flag unexpected UI modifications that might indicate a renderer compromise.

Generated by OpenCVE AI on July 17, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chromium Media Component Exploit Allows UI Spoofing via Renderer Compromise

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Renderer Compromise in Chrome Media Handling

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Renderer Compromise in Chrome Media Handling

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Media Implementation Allows UI Spoofing with Compromised Renderer

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Media Implementation Allows UI Spoofing with Compromised Renderer

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation permits UI Spoofing via Compromised Renderer

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation permits UI Spoofing via Compromised Renderer

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Media Handling in Chrome on Windows

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Media Handling in Chrome on Windows

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Process Isolation Vulnerability Enables UI Spoofing After Renderer Compromise

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Media Process Isolation Vulnerability Enables UI Spoofing After Renderer Compromise

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Enables Remote UI Spoofing

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Enables Remote UI Spoofing

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Allows UI Spoofing After Renderer Compromise

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Allows UI Spoofing After Renderer Compromise

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Compromised Renderer in Google Chrome for Windows

Thu, 02 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Compromised Renderer in Google Chrome for Windows

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Renderer UI Spoofing via Malformed Media Handling in Chrome

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Renderer UI Spoofing via Malformed Media Handling in Chrome

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Renderer Compromise in Google Chrome on Windows
Weaknesses CWE-1007

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Renderer Compromise in Google Chrome on Windows
Weaknesses CWE-1007

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:14:47.925Z

Reserved: 2026-06-29T23:03:55.136Z

Link: CVE-2026-13931

cve-icon Vulnrichment

Updated: 2026-07-01T15:14:42.283Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:30:17Z

Weaknesses