Description
Insufficient validation of untrusted input in DataTransfer in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an input validation flaw in Google Chrome on Windows that allows a remote attacker who has already compromised the renderer process to deliver crafted HTML. The attacker can exploit insufficient sanitization of DataTransfer data to cause the browser to render deceptive user interface elements, potentially luring users into unintended actions.

Affected Systems

Google Chrome for Windows is affected. All versions prior to 150.0.7871.47 contain the flaw. The fixed releases, beginning with 150.0.7871.47, validate DataTransfer input correctly.

Risk and Exploitability

The flaw receives a CVSS score of 6.5, indicating medium severity. The EPSS score of <1% suggests a low likelihood of exploitation at present. It is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Exploitation requires an attacker first to compromise the renderer process; after that, supplied crafted HTML can bypass validation and perform UI spoofing. The risk is bounded to the scope of the renderer and the integrity of the browser’s UI.

Generated by OpenCVE AI on July 17, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome 150.0.7871.47 or newer
  • Enable Chrome automatic updates so future security fixes are applied automatically
  • Educate users to recognize UI spoofing and verify unexpected interface changes

Generated by OpenCVE AI on July 17, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome DataTransfer Input Validation Flaw Enables UI Spoofing

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chrome DataTransfer Input Validation Flaw Enables UI Spoofing

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unvalidated DataTransfer Input Enables UI Spoofing in Google Chrome on Windows

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unvalidated DataTransfer Input Enables UI Spoofing in Google Chrome on Windows

Sun, 12 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Allows UI Spoofing via DataTransfer in Chrome

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Allows UI Spoofing via DataTransfer in Chrome

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DataTransfer Leading to UI Spoofing in Chrome on Windows

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DataTransfer Leading to UI Spoofing in Chrome on Windows

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Input Validation Failure in DataTransfer Causes UI Spoofing in Chrome

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Input Validation Failure in DataTransfer Causes UI Spoofing in Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unvalidated DataTransfer Input Enables UI Spoofing via Renderer Process Compromise

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unvalidated DataTransfer Input Enables UI Spoofing via Renderer Process Compromise

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated DataTransfer in Google Chrome

Sat, 04 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated DataTransfer in Google Chrome

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Windows UI Spoofing via Unvalidated DataTransfer

Fri, 03 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome Windows UI Spoofing via Unvalidated DataTransfer

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Untrusted DataTransfer Input Allows UI Spoofing in Chrome Windows

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Untrusted DataTransfer Input Allows UI Spoofing in Chrome Windows

Thu, 02 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DataTransfer Leads to UI Spoofing in Chrome on Windows

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of DataTransfer Leads to UI Spoofing in Chrome on Windows

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome DataTransfer

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome DataTransfer

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in DataTransfer in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:58:52.847Z

Reserved: 2026-06-29T23:04:11.957Z

Link: CVE-2026-13990

cve-icon Vulnrichment

Updated: 2026-07-01T17:09:07.767Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation