Description
Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the Credential Management subsystem of Android Chrome and allows a remote attacker to craft a malicious HTML page that displays a forged user interface. The deception can mislead a user into interacting with a credential prompt that is not authentic to Google Chrome, potentially causing the user to enter sensitive information or submit data to an attacker. The vulnerability does not directly expose stored credentials or elevate privileges.

Affected Systems

Google Chrome for Android versions earlier than 150.0.7871.47 are affected. Any build of the Chrome browser on Android devices that predates this version is vulnerable to the UI‑spoofing exploit.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity while the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only the delivery of a crafted HTML page to the victim, which a remote attacker can achieve through a malicious website or a compromised network resource. No privileged access is needed on the target device, and the attack vector is remote via network traffic.

Generated by OpenCVE AI on July 31, 2026 at 16:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later, which contains the fix for the UI spoofing flaw.
  • Enable automatic updates for Chrome or manually download and install the latest security update from the device manufacturer to keep the browser current.
  • If an immediate upgrade is not possible, consider using an alternative browser that applies stricter update policies or temporarily disable Chrome until the vulnerability is patched.

Generated by OpenCVE AI on July 31, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management Exploit in Google Chrome for Android

Mon, 27 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management Exploit in Google Chrome for Android

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Android Chrome UI Spoofing via Credential Management Flaw

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Android Chrome UI Spoofing via Credential Management Flaw

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Credential Management UI Spoofing Vulnerability

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Credential Management UI Spoofing Vulnerability

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Chrome on Android

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Credential Management of Google Chrome for Android

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Credential Management of Google Chrome for Android

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome Android Credential Management

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome Android Credential Management

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Credential Management UI Spoofing Vulnerability in Google Chrome for Android

Sat, 04 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Credential Management UI Spoofing Vulnerability in Google Chrome for Android

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Google Chrome for Android

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Credential Management in Google Chrome for Android

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Credential Management

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Credential Management Flaw

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Credential Management Flaw

Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for Android

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for Android

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:11.202Z

Reserved: 2026-06-29T23:04:13.181Z

Link: CVE-2026-13994

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:46.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:15:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information