Description
Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome’s handling of password prompts allows a remote attacker who has already compromised the renderer process to deliver a spoofed password UI through a crafted HTML page. Because the attacker can masquerade the browser’s security dialog, a user may unknowingly enter credentials or other sensitive data into a fake prompt. This vulnerability is classified as CWE‑451, reflecting a broken UI‑security boundary.

Affected Systems

All Google Chrome installations built before version 150.0.7871.47 on any supported operating system are affected. The issue is confined to the renderer process that displays password interfaces.

Risk and Exploitability

Exploiting this flaw requires a prior compromise of the renderer process, typically via malicious content or another vulnerability. The CVSS score of 3.1 indicates a low severity, and an EPSS score of less than 1% shows a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits yet. Nevertheless, if an attacker can subvert renderer code, the spoofed password prompt could be used for phishing attacks.

Generated by OpenCVE AI on July 21, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 150.0.7871.47 or newer.
  • Enable Chrome’s Safe Browsing feature to help detect and block deceptive pages.
  • Keep the operating system, anti‑virus, and anti‑malware products fully updated to defend against payloads that could compromise the renderer process.

Generated by OpenCVE AI on July 21, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt Spoofing via Compromised Renderer

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt Spoofing via Compromised Renderer

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing Vulnerability via Password Prompts

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing Vulnerability via Password Prompts

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Password UI Spoofing via Compromised Renderer

Fri, 10 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Password UI Spoofing via Compromised Renderer

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Incorrect Password Prompt UI Allows UI Spoofing in Chrome

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Incorrect Password Prompt UI Allows UI Spoofing in Chrome

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Password Prompt UI Spoofing in Google Chrome

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Password Prompt UI Spoofing in Google Chrome

Mon, 06 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Password Prompt Handling in Chrome

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Password Prompt Handling in Chrome

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Password UI Spoofing Vulnerability

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Password UI Spoofing Vulnerability

Fri, 03 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt UI Spoofing Vulnerability

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt UI Spoofing Vulnerability

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Compromised Renderer Process

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Compromised Renderer Process

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt UI Spoofing via Renderer Compromise
Weaknesses CWE-639
CWE-800

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Password Prompt UI Spoofing via Renderer Compromise
Weaknesses CWE-639
CWE-800

Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Password Prompt in Google Chrome Pre‑150.0.7871.47
Weaknesses CWE-639
CWE-800

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Password Prompt in Google Chrome Pre‑150.0.7871.47
Weaknesses CWE-639
CWE-800

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:23:06.972Z

Reserved: 2026-06-29T23:04:07.932Z

Link: CVE-2026-13982

cve-icon Vulnrichment

Updated: 2026-07-01T19:22:58.232Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T16:30:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information