Description
Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability causes Chrome to omit or incorrectly display the domain in the password prompt, allowing a remote attacker to trick users into revealing credentials for a fraudulent site. This is a CWE‑1021 misuse of secure UI logic that poses a confidentiality risk by potentially enabling credential theft.

Affected Systems

All Google Chrome desktop installations running a version older than 151.0.7922.72 are affected. The issue does not apply to non‑desktop platforms or other vendors; the fix was released in the 151.0.7922.72 update.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium range. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis and it is not listed in CISA's KEV catalog. The attack surface is remote; a malicious web page can trigger the UI misbehavior without any additional pre‑conditions beyond a user visiting the page. Because the exploit is driven by a crafted HTML document, it could be deployed via a phishing email or compromised website, making the attack vector likely through social engineering. Due to the low exploitation probability and lack of widespread public exploitation reports, the immediate risk to a typical organization is moderate, but it remains important to mitigate.

Generated by OpenCVE AI on August 2, 2026 at 06:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to the latest stable release (≥ 151.0.7922.72) to apply the fix.
  • Enable automatic browser updates so future patches are applied promptly.
  • Provide user training on recognizing domain spoofing in password prompts and encourage safe browsing habits.

Generated by OpenCVE AI on August 2, 2026 at 06:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Incorrect security UI in Passwords
Weaknesses CWE-1021
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T15:43:05.730Z

Reserved: 2026-07-27T23:35:01.862Z

Link: CVE-2026-17840

cve-icon Vulnrichment

Updated: 2026-07-31T15:42:59.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:47.617

Modified: 2026-08-03T19:04:34.273

Link: CVE-2026-17840

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:36Z

Links: CVE-2026-17840 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:45:03Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information