
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13982 is an incorrect security UI vulnerability in the Passwords component of Google Chrome that allows UI spoofing via a crafted HTML page. It affects all versions of Google Chrome prior to 150.0.7871.47 on Windows/Mac and 150.0.7871.46 on Linux. The vulnerability was reported to Google on 2026-05-17 and publicly disclosed on 2026-06-30 as part of the Chrome 150 stable channel release. It carries a CVSS v3.1 base score of 3.1 (Low) (Chrome Advisory, Feedly).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's password manager security UI fails to correctly represent security-relevant information when the renderer process has been compromised. An attacker who has already achieved renderer process compromise can serve a crafted HTML page that causes the Passwords UI to display misleading or spoofed security indicators to the user. The attack vector is network-based, requires user interaction, and has high attack complexity due to the prerequisite of renderer process compromise (Chrome Advisory, Feedly).
Successful exploitation allows a remote attacker who has already compromised the Chrome renderer process to display a spoofed password manager security UI, potentially deceiving users into believing their credentials are safe or into interacting with a fraudulent password interface. The primary impact is on integrity (low), as the attacker can manipulate what security information is presented to the user; there is no direct confidentiality or availability impact. This could facilitate credential theft or phishing by undermining user trust in Chrome's built-in password security indicators (Feedly).
Google has addressed this vulnerability in Chrome 150.0.7871.47 (Windows/Mac) and 150.0.7871.46 (Linux). Users and administrators should update Google Chrome to version 150.0.7871.47 or later immediately via the browser's built-in update mechanism or through enterprise deployment tools. No configuration-based workaround is available; upgrading to the patched version is the only recommended remediation (Chrome Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."