Description
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

extension framework before version 150.0.7871.47. A malicious extension that has been installed by the user can, allowing an attacker to deceive users into interacting with misleading or deceptive UI. The weakness is identified as CWE-451. No exploitation of system resources or data beyond UI deception is described.

Affected Systems

The vulnerability affects users of Google Chrome on desktop operating systems running versions older than 150.0.7871.47. The CVE text does not explicitly name particular OS platforms; this absence of explicit mention is an inferred assumption that desktop platforms are impacted, while Android, Chrome OS, or other non‑desktop environments are not specifically listed and therefore are presumed not to be affected.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to install a malicious extension, which typically depends on social engineering rather than network‑level or privileged‑access attacks. Consequently, the risk is primarily limited to attackers who can persuade users to add a suspicious extension.

Generated by OpenCVE AI on July 21, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later on all desktop installations.
  • Remove or disable any extensions installed before the update, particularly those that request permissions unrelated to their intended function.
  • Enforce enterprise policies to allow extension installation only from the Chrome Web Store or from trusted developers, and enable Safe Browsing features.

Generated by OpenCVE AI on July 21, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing due to Insufficient Policy Enforcement

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Insufficient Policy Enforcement

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Insufficient Policy Enforcement

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Enables UI Spoofing via Malicious Chrome Extension

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Enables UI Spoofing via Malicious Chrome Extension

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Insufficient policy enforcement in Chrome extensions allows UI spoofing

Tue, 07 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Insufficient policy enforcement in Chrome extensions allows UI spoofing

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension Due to Insufficient Policy Enforcement

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension Due to Insufficient Policy Enforcement

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Malicious Extension

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Malicious Extension

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Policy Enforcement Failure
Weaknesses CWE-284

Thu, 02 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Policy Enforcement Failure
Weaknesses CWE-284

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Insufficient Policy Enforcement
Weaknesses CWE-272
CWE-279

Wed, 01 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Insufficient Policy Enforcement
Weaknesses CWE-272
CWE-279

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T00:41:18.701Z

Reserved: 2026-06-29T23:03:59.224Z

Link: CVE-2026-13948

cve-icon Vulnrichment

Updated: 2026-07-01T19:26:24.528Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information