Description
Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw involves incorrect rendering of Chrome’s security indicators in the TabStrip. A crafted HTML page can cause secure icons to appear for an unsecured connection, misleading users into believing the site is protected. Classified as CWE‑290 and CWE‑451, the vulnerability does not grant code execution or disclosure but enables phishing or social‑engineering attacks by exploiting users’ trust.

Affected Systems

All installations of Google Chrome with revisions earlier than 150.0.7871.47, across Windows, macOS, Linux, and other supported platforms, are affected because the defect is present in the common code base of all released builds before that revision.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity. The EPSS score of less than 1% and the absence of the vulnerability from the CISA KEV catalog suggest a very low likelihood of real‑world exploitation. An attacker can simply host a malicious webpage that a user visits; the attack does not require elevated privileges or code execution, but relies on social‑engineering tactics to coerce users into submitting sensitive information over a page that appears to be secure.

Generated by OpenCVE AI on August 12, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 150.0.7871.47 or newer to remove the UI spoofing flaw.
  • Require automatic updates or enforce update policies across managed Chrome installations to ensure the patch is installed.
  • Educate users to verify the lock icon during sensitive transactions and to report suspicious UI changes.

Generated by OpenCVE AI on August 12, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 12 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security Indicators

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security Indicators

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Security UI in Chrome TabStrip

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Security UI in Chrome TabStrip

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Allows Attacker to Display Fake Secure Indicators

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Allows Attacker to Display Fake Secure Indicators

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip Security UI

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip Security UI

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Incorrect Security UI in Chrome TabStrip Enables Remote UI Spoofing

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Incorrect Security UI in Chrome TabStrip Enables Remote UI Spoofing

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing via Incorrect Security Indicator

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing via Incorrect Security Indicator

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip via Crafted HTML Page

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip via Crafted HTML Page

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Google Chrome TabStrip UI Spoofing Vulnerability

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Google Chrome TabStrip UI Spoofing Vulnerability

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Misleading Secure Connection Indicators

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Misleading Secure Connection Indicators

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security UI in TabStrip
Weaknesses CWE-151
CWE-653

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security UI in TabStrip
Weaknesses CWE-151
CWE-653

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:50.494Z

Reserved: 2026-06-29T23:04:08.451Z

Link: CVE-2026-13984

cve-icon Vulnrichment

Updated: 2026-07-01T15:16:00.263Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:17:11.707

Modified: 2026-07-02T15:34:15.943

Link: CVE-2026-13984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:30:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information