Description
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published: 2026-05-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome DevTools contains insufficient policy enforcement that permits a malicious extension to perform UI spoofing if a user is convinced to install it. The crafted extension can manipulate the appearance of DevTools, potentially deceiving users into interacting with a falsified interface. Chromium classifies this flaw as low severity, indicating that its impact is confined to user deception rather than direct data compromise or system takeover.

Affected Systems

Any installation of Google Chrome before version 148.0.7778.96 is affected. All earlier stable releases can be exploited if an attacker achieves installation of a malicious extension.

Risk and Exploitability

The CVE is not listed in CISA’s KEV catalog, indicating limited public information about exploitation. The likely attack vector is social engineering that results in the user installing a malicious extension. An attacker does not need network privileges or remote access; the vulnerability is limited to the user’s browser session and the DevTools UI. Given the low severity rating, the overall risk to sensitive data or system integrity is minimal, although deceptive interfaces could lead to phishing or credential theft. The CVSS score for this vulnerability is 5.4.

Generated by OpenCVE AI on May 7, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 148.0.7778.96 or later
  • Remove or disable any suspicious or untrusted extensions
  • Restrict extension installation to trusted sources and carefully review extension permissions

Generated by OpenCVE AI on May 7, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 01:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing in Chrome DevTools via Malicious Extension

Thu, 07 May 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Malicious Chrome Extension in DevTools
Weaknesses CWE-284

Wed, 06 May 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 06 May 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Malicious Chrome Extension in DevTools
Weaknesses CWE-284

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:47:40.718Z

Reserved: 2026-05-05T22:59:33.341Z

Link: CVE-2026-8006

cve-icon Vulnrichment

Updated: 2026-05-06T21:20:18.024Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-06T19:16:51.580

Modified: 2026-05-06T22:16:44.720

Link: CVE-2026-8006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:30:17Z

Weaknesses