Description
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the password prompt implementation of Google Chrome. A crafted HTML page can trigger a malicious login interface that mimics the browser’s native dialog, deceiving users into entering credentials into a spoofed prompt. While the CVE description does not explicitly claim credential theft, the UI spoofing mechanism could enable a social‑engineering attacker to harvest user input if the user believes the prompt is legitimate.

Affected Systems

All Google Chrome versions prior to 150.0.7871.47 on all platforms are affected. Users running the stable channel before this build, regardless of operating system, must address the issue by upgrading to a fixed release.

Risk and Exploitability

This flaw is a Medium‑severity vulnerability per Chromium’s internal rating. The attack requires a social‑engineering vector; the attacker must deliver a malicious web page containing the crafted HTML to the victim. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation likelihood remains unknown. Nonetheless, until the browser is updated, the flaw remains a usable phishing vector.

Generated by OpenCVE AI on July 1, 2026 at 05:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, which removes the flawed password prompt implementation.
  • Avoid entering credentials on unexpected or suspicious prompts; verify that a login form originates from a legitimate site before submitting sensitive information.
  • Enable multi‑factor authentication on accounts that may be targeted, adding an extra layer of protection against credential compromise.

Generated by OpenCVE AI on July 1, 2026 at 05:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt UI Spoofing Vulnerability in Unpatched Versions
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:38:36.579Z

Reserved: 2026-06-29T23:04:02.218Z

Link: CVE-2026-13960

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T05:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor