Description
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect security UI in WebAppInstalls in Google Chrome versions prior to 150.0.7871.47 allows a remote attacker who convinces a user to perform specific gestures in the browser to cause the UI to display a spoofed device security warning for a domain that does not match the page’s real origin. The attacker can deliver a crafted HTML page that tricks the user into thinking they are interacting with a legitimate site, potentially leading to phishing or credential theft. The flaw is an emulation of a domain, not a code execution or authentication bypass, and is rated medium severity by Chromium.

Affected Systems

The vulnerability affects unpatched desktop installations of Google Chrome older than version 150.0.7871.47. Those builds present the incorrect UI during WebAppInstalls, exposing users to crafted HTML pages that may trigger the exploit.

Risk and Exploitability

The CVSS score is 4.2, indicating a medium severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to perform specific, user‑initiated gestures prompted by a malicious web page, meaning the risk is greatest in the context of social engineering or phishing attacks. No publicly known workaround exists beyond avoiding the risky UI interactions.

Generated by OpenCVE AI on July 1, 2026 at 13:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later
  • Configure Chrome to alert users before installing or interacting with web app prompts
  • Disable or limit the use of WebAppInstalls for untrusted sites via policy settings

Generated by OpenCVE AI on July 1, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Chrome Security UI Incorrectness Enables Domain Spoofing via Web App Installs

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome Security UI Incorrectness Enables Domain Spoofing via Web App Installs

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:58:15.258Z

Reserved: 2026-06-29T23:04:12.877Z

Link: CVE-2026-13993

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:41.902Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:00:06Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information