Description
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome extensions prior to 150.0.7871.47 allows an attacker who convinces a user to install a malicious extension to perform UI spoofing through a crafted Chrome extension. The flaw is an input validation weakness (CWE-20), enabling the attacker to display user interfaces that mimic legitimate browser prompts or other interface components, potentially leading to social engineering and data compromise.

Affected Systems

Google Chrome versions before 150.0.7871.47 are affected. The issue applies to the stable channel across all platforms where Chrome runs, though specific operating systems are not listed in the advisory.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to persuade a user to install a malicious extension; once installed, the extension can present spoofed UI elements. The vulnerability does not require additional system compromise beyond the user’s installation decision.

Generated by OpenCVE AI on August 2, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 150.0.7871.47 or later to apply the official fix.
  • Remove or reevaluate any extensions installed before the update that cannot be verified as trustworthy.
  • In managed environments, configure Chrome policy to allow installation only from the Chrome Web Store or signed extensions, blocking untrusted extensions.

Generated by OpenCVE AI on August 2, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Sun, 02 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome extensions leading to UI spoofing

Thu, 16 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome extensions leading to UI spoofing

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Untrusted Extension Input

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Untrusted Extension Input

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability in Versions Prior to 150.0.7871.47

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability in Versions Prior to 150.0.7871.47

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Extensions Enabling UI Spoofing

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Extensions Enabling UI Spoofing

Tue, 07 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Input Validation Flaw

Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing via Input Validation Flaw

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability via Malicious Extension

Sun, 05 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Spoofing Vulnerability via Malicious Extension

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension Due to Insufficient Input Validation

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension Due to Insufficient Input Validation

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Unvalidated Extension Input

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension due to Unvalidated Extension Input

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension with Insufficient Input Validation

Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension with Insufficient Input Validation

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Extension Input Enables UI Spoofing in Google Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Extension Input Enables UI Spoofing in Google Chrome
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:28:21.246Z

Reserved: 2026-06-29T23:04:14.555Z

Link: CVE-2026-13999

cve-icon Vulnrichment

Updated: 2026-07-01T14:28:11.348Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation