Description
Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incorrect security UI in Chrome Extensions on Android before version 150.0.7871.47 allows a remote attacker to craft an HTML page that convinces a user to perform specific gestures, enabling the attacker to spoof the UI. This flaw can deceive a user into interacting with a fake interface, potentially leading to social engineering or other malicious actions. The impact is a user interface deception vulnerability, classified with medium severity in Chromium’s internal security rating.

Affected Systems

Google Chrome for Android, versions prior to 150.0.7871.47 are affected.

Risk and Exploitability

The exploit requires a crafted HTML page that presents misleading UI elements, and the attacker must convince a user to engage with particular UI gestures. Because the flaw is limited to the UI layer, it does not provide direct code execution, but it elevates the risk of phishing attacks. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The medium severity still warrants prompt remediation through an update to a fixed Chrome version, as the vulnerability can be triggered by a remote web page exposed to the user.

Generated by OpenCVE AI on July 1, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android devices to version 150.0.7871.47 or later.
  • Remove or disable any extensions that have not been updated to the fixed version.
  • Apply any available vendor security patches or updates from Google as soon as they are released.
  • Consider disabling or revoking permissions for extensions that can display custom UI elements if an update cannot be applied immediately.

Generated by OpenCVE AI on July 1, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Crafted HTML Page

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Chrome Android UI Spoofing via Crafted HTML Page

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing through Crafted HTML in Chrome Android Extensions
Weaknesses CWE-853

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing through Crafted HTML in Chrome Android Extensions
Weaknesses CWE-853

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:58:00.873Z

Reserved: 2026-06-29T23:04:13.982Z

Link: CVE-2026-13997

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:39.686Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T16:00:16Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information