Description
Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an improper implementation of the Media component in Google Chrome on Windows, which permits a remote attacker who has already taken control of the renderer process to load a specially crafted HTML page that causes the browser’s user interface to be spoofed. This flaw is an instance of CWE-284, an access control weakness that allows UI manipulation and could mislead users about the source or authenticity of the displayed content.

Affected Systems

Google Chrome browsers running on Windows with versions older than 150.0.7871.47 are affected. Systems that have not applied the 150.0.7871.47 or newer patch are vulnerable to this UI spoofing flaw.

Risk and Exploitability

The CVSS score of 6.5 characterizes the vulnerability as medium severity, while an EPSS score of less than 1 % indicates a low likelihood of widespread exploitation in the general population. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to first compromise the renderer process, after which an attacker can deliver a crafted HTML page to alter the UI. Because the technique depends on a prior renderer compromise, the overall risk remains moderate, but any system that is susceptible to renderer exploitation should treat this flaw as a potential vector for UI manipulation.

Generated by OpenCVE AI on August 3, 2026 at 06:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to receive the Media component fix.
  • Configure Chrome to run renderer processes with stricter isolation by enabling the appropriate command‑line flags or settings, which limits a compromised renderer’s ability to alter the UI.
  • Implement browser‑level monitoring or endpoint detection to flag unexpected UI modifications that could indicate renderer compromise.

Generated by OpenCVE AI on August 3, 2026 at 06:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Compromised Renderer in Windows Chrome

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Component Render Process User Interface Spoofing Vulnerability

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome Media Component Render Process User Interface Spoofing Vulnerability

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chromium Media Component Exploit Allows UI Spoofing via Renderer Compromise

Fri, 17 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chromium Media Component Exploit Allows UI Spoofing via Renderer Compromise

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Renderer Compromise in Chrome Media Handling

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Renderer Compromise in Chrome Media Handling

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Media Implementation Allows UI Spoofing with Compromised Renderer

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Media Implementation Allows UI Spoofing with Compromised Renderer

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation permits UI Spoofing via Compromised Renderer

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation permits UI Spoofing via Compromised Renderer

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Media Handling in Chrome on Windows

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Media Handling in Chrome on Windows

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Process Isolation Vulnerability Enables UI Spoofing After Renderer Compromise

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Media Process Isolation Vulnerability Enables UI Spoofing After Renderer Compromise

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Enables Remote UI Spoofing

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Enables Remote UI Spoofing

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Allows UI Spoofing After Renderer Compromise

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Implementation Allows UI Spoofing After Renderer Compromise

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Compromised Renderer in Google Chrome for Windows

Thu, 02 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Compromised Renderer in Google Chrome for Windows

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Renderer UI Spoofing via Malformed Media Handling in Chrome

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Renderer UI Spoofing via Malformed Media Handling in Chrome

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Renderer Compromise in Google Chrome on Windows
Weaknesses CWE-1007

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Renderer Compromise in Google Chrome on Windows
Weaknesses CWE-1007

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:14:47.925Z

Reserved: 2026-06-29T23:03:55.136Z

Link: CVE-2026-13931

cve-icon Vulnrichment

Updated: 2026-07-01T15:14:42.283Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:45:04Z

Weaknesses