Description
Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an incorrect handling of the security indicators in the Chrome TabStrip. A crafted HTML page can cause the browser to display secure icons for an unsecured connection, leading users to believe a site is protected. This flaw is classified as CWE‑451 and does not provide code execution or data exfiltration but can mislead users about the state of their connection.

Affected Systems

All installations of Google Chrome with revisions earlier than 150.0.7871.47 are impacted. The defect exists in the same code base across the released builds, so every platform version of Chrome before the stated revision remains vulnerable until the update is applied.

Risk and Exploitability

The CVSS score of 4.3 classifies the issue as low severity. The EPSS score, being less than 1%, and its absence from the CISA KEV catalog suggest a very low likelihood of real‑world exploitation. An attacker merely needs to host a malicious web page that a user visits. The primary threat is a social‑engineering attack causing users to submit sensitive data over what appears to be a secure connection.

Generated by OpenCVE AI on July 21, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome 150.0.7871.47 or later to remove the UI spoofing flaw.
  • Configure enterprise update policies or group policies that enable automatic updates so all managed Chrome installations receive the patch promptly.
  • Train users to verify the presence of the lock icon and be cautious when entering personal data on pages that appear secure but may not be, reporting suspicious UI changes.

Generated by OpenCVE AI on July 21, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Security UI in Chrome TabStrip

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Allows Attacker to Display Fake Secure Indicators

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Allows Attacker to Display Fake Secure Indicators

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip Security UI

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip Security UI

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Incorrect Security UI in Chrome TabStrip Enables Remote UI Spoofing

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Incorrect Security UI in Chrome TabStrip Enables Remote UI Spoofing

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing via Incorrect Security Indicator

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing via Incorrect Security Indicator

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip via Crafted HTML Page

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome TabStrip via Crafted HTML Page

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Google Chrome TabStrip UI Spoofing Vulnerability

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Google Chrome TabStrip UI Spoofing Vulnerability

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Misleading Secure Connection Indicators

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Misleading Secure Connection Indicators

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security UI in TabStrip
Weaknesses CWE-151
CWE-653

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Incorrect Security UI in TabStrip
Weaknesses CWE-151
CWE-653

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:50.494Z

Reserved: 2026-06-29T23:04:08.451Z

Link: CVE-2026-13984

cve-icon Vulnrichment

Updated: 2026-07-01T15:16:00.263Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T16:30:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information