
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13991 is a UI spoofing vulnerability in Google Chrome for iOS caused by insufficient validation of untrusted input. It affects Google Chrome on iOS prior to version 150.0.7871.47 and allows a remote, unauthenticated attacker to perform UI spoofing via a crafted HTML page. The vulnerability was disclosed on June 30, 2026, and patched as part of the Chrome 150 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Medium severity by the Chromium security team (Chrome Releases, Feedly).
The root cause is classified under CWE-20 (Improper Input Validation) and CWE-451 (User Interface Misrepresentation of Critical Information). Chrome for iOS fails to adequately validate untrusted HTML input, allowing a crafted page to manipulate browser UI elements — such as the address bar or security indicators — to misrepresent the origin or nature of content being displayed. The attack vector is network-based, requires no privileges, and requires user interaction (visiting a malicious page). No public proof-of-concept code has been identified (Feedly, Chrome Releases).
Successful exploitation allows a remote attacker to deceive iOS users into believing they are interacting with a legitimate website or trusted browser interface, enabling phishing, credential harvesting, or social engineering attacks. The integrity impact is limited (low), with no direct confidentiality or availability impact. The vulnerability does not enable code execution or lateral movement, but can serve as a stepping stone for more targeted attacks against users who trust spoofed UI elements (Feedly).
Update Google Chrome on iOS to version 150.0.7871.47 or later, which was released on June 30, 2026, as part of the Chrome 150 stable channel update. No configuration-based workaround is available; upgrading is the only effective remediation. Users should also exercise caution when visiting unfamiliar websites and verify browser UI elements, particularly address bars and security indicators, when handling sensitive information (Chrome Releases, Microsoft MSRC).
The vulnerability was noted by CIS (Center for Internet Security) as part of a broader advisory covering multiple vulnerabilities in Google Chrome that could allow for arbitrary code execution and other impacts. Kaspersky also catalogued the vulnerability in their threat database. No significant independent researcher commentary or notable social media discussion has been identified specific to CVE-2026-13991, consistent with its medium severity and limited exploitation potential (CIS Advisory, Kaspersky).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."