Description
Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the macOS UI handling of Google Chrome allows a remote attacker who convinces a user to perform specific gesture interactions to spoof the user interface through a crafted HTML page. The core weakness lies in improper handling of gesture events, enabling deceptive interface content that can mislead the user into thinking they are interacting with legitimate UI elements.

Affected Systems

The vulnerability affects Google Chrome for macOS prior to version 150.0.7871.47. All users running those builds are at risk.

Risk and Exploitability

The CVSS score of 4.2 indicates a Medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate but non‑immediate threat level. Successful exploitation requires the user to engage in a specific gesture sequence after visiting a malicious HTML page, meaning the attack vector is user‑dependent and not purely automated. Based on the description, it is inferred that the attacker could use social engineering to get a user to perform the required gesture sequence.

Generated by OpenCVE AI on July 1, 2026 at 13:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Google Chrome release notes for updates addressing UI spoofing on macOS and install any available patches.
  • Avoid performing the gesture interactions targeted by the exploit when visiting unfamiliar or untrusted webpages.
  • Enable automatic updates so that future patches for unrelated defects are applied promptly.

Generated by OpenCVE AI on July 1, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Mac Chrome pre 150.0.7871.47

Wed, 01 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Mac Chrome pre 150.0.7871.47

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:58:29.670Z

Reserved: 2026-06-29T23:04:12.525Z

Link: CVE-2026-13992

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:43.978Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:00:06Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information