Description
Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome’s Autofill implementation on Android allows an attacker to load a crafted web page that presents a forged user‑interface element that looks like a Chrome form. This UI spoofing can convince a user to enter sensitive data, such as passwords or credit‑card details, under the false belief that it comes from the browser. The flaw maps to CWE‑451 and can compromise confidentiality and integrity of user‑supplied information.

Affected Systems

Google Chrome for Android versions prior to 150.0.7871.47 are affected. The vulnerability is limited to the Android platform and does not influence desktop or other operating‑system editions.

Risk and Exploitability

The bug can be triggered remotely by hosting a malicious page that a user visits. The likely requirement is that it operates without elevated privileges and depends on user interaction with the spoofed form. With a CVSS score of 4.3 and an EPSS lower than 1 %, the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based interaction with a deceptive page.

Generated by OpenCVE AI on July 15, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome for Android to version 150.0.7871.47 or later.
  • Disable the Autofill feature in Chrome’s Settings to mitigate the spoofing risk.
  • Exercise caution with unexpected prompts or forms on web pages and confirm their source before interacting.

Generated by OpenCVE AI on July 15, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing via Crafted Web Page

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing via Crafted Web Page

Sun, 12 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Autofill in Google Chrome on Android

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Autofill in Google Chrome on Android

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Tue, 07 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Sun, 05 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing Vulnerability on Android

Sun, 05 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability Allowing Remote Web Page Attacks

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability Allowing Remote Web Page Attacks

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Autofill in Google Chrome for Android

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Autofill in Google Chrome for Android

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Android Autofill UI Spoofing Vulnerability

Thu, 02 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Google Chrome Android Autofill UI Spoofing Vulnerability

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill UI Spoofing Vulnerability

Wed, 01 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing via Malformed HTML
Weaknesses CWE-1021

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chrome Autofill UI Spoofing via Malformed HTML
Weaknesses CWE-1021

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:52:40.273Z

Reserved: 2026-06-29T23:11:48.828Z

Link: CVE-2026-14134

cve-icon Vulnrichment

Updated: 2026-07-01T14:52:36.254Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T10:30:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information