Description
Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw originates from an inappropriate implementation within the Permissions handling of Google Chrome before build 150.0.7871.47. A remote attacker can deliver a crafted HTML page that triggers a forged permission request dialog, leading users to grant permissions they would otherwise deny. This is a purely deceptive UI manipulation and does not provide code execution or denial of service. The weakness is identified as CWE‑451.

Affected Systems

Google Chrome desktop builds on the stable channel released prior to version 150.0.7871.47 are vulnerable. Users who have not updated to the patched build are at risk, including all desktop deployments of the stable channel older than this build.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a malicious HTML page delivered to the victim and relies on user interaction; no privilege escalation or credential compromise is needed. The likely attack vector is remote via a malicious web page, and the flaw is associated with CWE‑451.

Generated by OpenCVE AI on July 31, 2026 at 16:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to remove the UI spoofing flaw.
  • In managed environments, enforce enterprise policy restrictions that limit permission requests to trusted domains, thereby reducing exposure.
  • Educate users to verify the authenticity of permission dialogs before accepting them.

Generated by OpenCVE AI on July 31, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome Permissions

Sat, 25 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome Permissions

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing Vulnerability

Fri, 17 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing Vulnerability

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Permission Prompt UI Spoofing in Google Chrome

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Permission Prompt UI Spoofing in Google Chrome

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Permission Prompt UI Spoofing in Google Chrome

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Permission Prompt UI Spoofing in Google Chrome

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Permission Prompts in Google Chrome

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Permission Prompts in Google Chrome

Wed, 08 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing via Crafted Page

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing via Crafted Page

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing Vulnerability

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing Vulnerability

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing Vulnerability

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing Vulnerability

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt Spoofing Vulnerability

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt Spoofing Vulnerability

Thu, 02 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome Permission Prompt UI Spoofing

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Permissions API in Google Chrome
Weaknesses CWE-1021

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Permissions API in Google Chrome
Weaknesses CWE-1021

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing via Crafted HTML
Weaknesses CWE-819

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Permissions UI Spoofing via Crafted HTML
Weaknesses CWE-819

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:05:58.906Z

Reserved: 2026-06-29T23:04:13.705Z

Link: CVE-2026-13996

cve-icon Vulnrichment

Updated: 2026-07-01T14:50:13.140Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:15:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information