Description
Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an input validation flaw in Chrome's WebShare feature for Android, classified as CWE‑20. An attacker who has already compromised the renderer process can supply a crafted HTML page that causes the browser to render misleading user interface elements. This allows the attacker to trick users into interacting with content that appears legitimate, potentially exposing sensitive information or enabling further attacks. The flaw does not provide remote code execution; its primary impact is UI spoofing.

Affected Systems

Affected systems are installations of Google Chrome on Android with versions older than 150.0.7871.47. No vendor information is provided for desktop or other platforms, so it is inferred that the flaw applies only to the Android version; the status for other releases is not documented in the CVE.

Risk and Exploitability

The base CVSS score of 3.1 indicates low overall severity. The EPSS score is under 1 %, and the issue is not listed in CISA KEV, implying a very small exploitation probability. The attacker must first compromise the renderer process, which limits the attack surface. The likely attack vector is a compromised renderer providing a specially crafted page, and the impact is confined to UI spoofing rather than code execution.

Generated by OpenCVE AI on August 4, 2026 at 08:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on Android to version 150.0.7871.47 or later
  • Configure your web applications to disable the WebShare feature unless it is required
  • Keep the Android operating system and security tools updated to reduce the likelihood of renderer compromise

Generated by OpenCVE AI on August 4, 2026 at 08:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome Android WebShare Feature Enables UI Spoofing through Compromised Renderer

Wed, 29 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare in Chrome on Android

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare in Chrome on Android

Tue, 21 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Chrome WebShare UI Spoofing Vulnerability on Android

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome WebShare UI Spoofing Vulnerability on Android

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated WebShare Input in Chrome on Android

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated WebShare Input in Chrome on Android

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation Flaw in Chrome Android

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation Flaw in Chrome Android

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome WebShare allows UI spoofing via compromised renderer

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome WebShare allows UI spoofing via compromised renderer

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via WebShare Input Validation

Tue, 07 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via WebShare Input Validation

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing Vulnerability via WebShare Input Validation

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing Vulnerability via WebShare Input Validation

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome WebShare UI Spoofing via Unvalidated Input

Sat, 04 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome WebShare UI Spoofing via Unvalidated Input

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Validation in Chrome WebShare on Android

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Validation in Chrome WebShare on Android

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation in Chrome Android

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation in Chrome Android

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation Flaw in Chrome for Android

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare Input Validation Flaw in Chrome for Android

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare in Chrome on Android when Renderer Process Compromised

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebShare in Chrome on Android when Renderer Process Compromised

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Untrusted WebShare Input

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Untrusted WebShare Input

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:29:09.157Z

Reserved: 2026-06-29T23:03:57.058Z

Link: CVE-2026-13939

cve-icon Vulnrichment

Updated: 2026-07-01T19:29:05.103Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:17:07.670

Modified: 2026-07-02T16:43:04.347

Link: CVE-2026-13939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation