CVE-2026-13982
vulnerability analysis and mitigation

Overview

CVE-2026-13982 is an incorrect security UI vulnerability in the Passwords component of Google Chrome that allows UI spoofing via a crafted HTML page. It affects all versions of Google Chrome prior to 150.0.7871.47 on Windows/Mac and 150.0.7871.46 on Linux. The vulnerability was reported to Google on 2026-05-17 and publicly disclosed on 2026-06-30 as part of the Chrome 150 stable channel release. It carries a CVSS v3.1 base score of 3.1 (Low) (Chrome Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's password manager security UI fails to correctly represent security-relevant information when the renderer process has been compromised. An attacker who has already achieved renderer process compromise can serve a crafted HTML page that causes the Passwords UI to display misleading or spoofed security indicators to the user. The attack vector is network-based, requires user interaction, and has high attack complexity due to the prerequisite of renderer process compromise (Chrome Advisory, Feedly).

Impact

Successful exploitation allows a remote attacker who has already compromised the Chrome renderer process to display a spoofed password manager security UI, potentially deceiving users into believing their credentials are safe or into interacting with a fraudulent password interface. The primary impact is on integrity (low), as the attacker can manipulate what security information is presented to the user; there is no direct confidentiality or availability impact. This could facilitate credential theft or phishing by undermining user trust in Chrome's built-in password security indicators (Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 150.0.7871.47 (Windows/Mac) and 150.0.7871.46 (Linux). Users and administrators should update Google Chrome to version 150.0.7871.47 or later immediately via the browser's built-in update mechanism or through enterprise deployment tools. No configuration-based workaround is available; upgrading to the patched version is the only recommended remediation (Chrome Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management