Description
Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an inappropriate implementation in Credential Management that enables a remote attacker to perform UI spoofing via a crafted HTML page. The weakness falls under CWE‑451, indicating a failure to enforce authentication checks that can lead to deceptive user interfaces. Although the flaw does not directly allow credential theft, a forged credential‑prompt interface could trick users into entering sensitive information or performing unintended actions.

Affected Systems

Google Chrome for Android builds prior to 150.0.7871.47 are affected.

Risk and Exploitability

CVSS score of 4.3 indicates medium severity. EPSS < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The attack appears to be remotely triggered by a crafted HTML page; no additional privileges are required.

Generated by OpenCVE AI on July 17, 2026 at 14:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47, which includes the fix.
  • Ensure Chrome is set to download and install updates automatically; if not, manually install security updates from your device manufacturer.
  • Remain vigilant for future advisories and consider using a browser that enforces strict update policies if you cannot apply the patch immediately.

Generated by OpenCVE AI on July 17, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Android Chrome UI Spoofing via Credential Management Flaw

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Credential Management UI Spoofing Vulnerability

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Credential Management UI Spoofing Vulnerability

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Credential Management of Google Chrome for Android

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Credential Management of Google Chrome for Android

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome Android Credential Management

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome Android Credential Management

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Credential Management UI Spoofing Vulnerability in Google Chrome for Android

Sat, 04 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Credential Management UI Spoofing Vulnerability in Google Chrome for Android

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Google Chrome for Android

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Google Chrome for Android

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Credential Management Flaw

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Credential Management Flaw

Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for Android

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for Android

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:11.202Z

Reserved: 2026-06-29T23:04:13.181Z

Link: CVE-2026-13994

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:46.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information