Description
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an inappropriate implementation in Google Chrome’s password interface. An attacker could send malicious network traffic that tricks the browser into presenting a fake credential entry prompt. This UI spoofing can lead a user to enter sensitive information into a deceptive interface, matching the characteristics of CWE-1021 (Improper Verification of Resource Ownership) and CWE-451 (Improper Handling of Dynamic Content).

Affected Systems

Affected products include Google Chrome on desktop operating systems (Windows, macOS, and Linux) running the stable channel builds older than 151.0.7922.72. Users who rely on Chrome’s integrated password manager in those builds are potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.3 classifies this as low severity, and the EPSS score indicates a probability of exploitation of less than 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote: an adversary can use specially crafted traffic to trigger the spoofed prompt. The risk is confined to situations where the user interacts with the manipulated interface and could facilitate credential theft through phishing.

Generated by OpenCVE AI on August 3, 2026 at 11:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.72 or later.
  • Enable automatic updates to ensure future patches are applied automatically.
  • Apply network-level filtering or intrusion prevention rules to block anomalous traffic patterns that could trigger UI spoofing.
  • Educate users to verify the authenticity of password prompts before entering credentials.

Generated by OpenCVE AI on August 3, 2026 at 11:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Network Traffic in Chrome Passwords chromium-browser: chromium-browser: Inappropriate implementation in Passwords
Weaknesses CWE-1021
References
Metrics threat_severity

None

threat_severity

Low


Fri, 31 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Network Traffic in Chrome Passwords

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T16:08:04.708Z

Reserved: 2026-07-27T23:37:17.867Z

Link: CVE-2026-18010

cve-icon Vulnrichment

Updated: 2026-07-30T16:07:42.778Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:05.770

Modified: 2026-08-03T15:56:37.057

Link: CVE-2026-18010

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:26:06Z

Links: CVE-2026-18010 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:45:03Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information