CVE-2026-13991
vulnerability analysis and mitigation

Overview

CVE-2026-13991 is a UI spoofing vulnerability in Google Chrome for iOS caused by insufficient validation of untrusted input. It affects Google Chrome on iOS prior to version 150.0.7871.47 and allows a remote, unauthenticated attacker to perform UI spoofing via a crafted HTML page. The vulnerability was disclosed on June 30, 2026, and patched as part of the Chrome 150 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Medium severity by the Chromium security team (Chrome Releases, Feedly).

Technical details

The root cause is classified under CWE-20 (Improper Input Validation) and CWE-451 (User Interface Misrepresentation of Critical Information). Chrome for iOS fails to adequately validate untrusted HTML input, allowing a crafted page to manipulate browser UI elements — such as the address bar or security indicators — to misrepresent the origin or nature of content being displayed. The attack vector is network-based, requires no privileges, and requires user interaction (visiting a malicious page). No public proof-of-concept code has been identified (Feedly, Chrome Releases).

Impact

Successful exploitation allows a remote attacker to deceive iOS users into believing they are interacting with a legitimate website or trusted browser interface, enabling phishing, credential harvesting, or social engineering attacks. The integrity impact is limited (low), with no direct confidentiality or availability impact. The vulnerability does not enable code execution or lateral movement, but can serve as a stepping stone for more targeted attacks against users who trust spoofed UI elements (Feedly).

Exploitation steps

  1. Reconnaissance: Identify iOS users running Google Chrome versions prior to 150.0.7871.47, which can be inferred from user-agent strings in web server logs or targeted phishing campaigns.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that exploits the insufficient input validation in Chrome for iOS to manipulate browser UI elements (e.g., spoofing the address bar, security lock icon, or page origin indicators).
  3. Deliver to target: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing email, SMS, or malicious link — requiring user interaction.
  4. UI spoofing achieved: When the victim visits the page in a vulnerable Chrome for iOS version, the browser renders manipulated UI elements, deceiving the user into believing they are on a legitimate site, facilitating credential theft or further social engineering (Chrome Releases, Feedly).

Mitigation and workarounds

Update Google Chrome on iOS to version 150.0.7871.47 or later, which was released on June 30, 2026, as part of the Chrome 150 stable channel update. No configuration-based workaround is available; upgrading is the only effective remediation. Users should also exercise caution when visiting unfamiliar websites and verify browser UI elements, particularly address bars and security indicators, when handling sensitive information (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was noted by CIS (Center for Internet Security) as part of a broader advisory covering multiple vulnerabilities in Google Chrome that could allow for arbitrary code execution and other impacts. Kaspersky also catalogued the vulnerability in their threat database. No significant independent researcher commentary or notable social media discussion has been identified specific to CVE-2026-13991, consistent with its medium severity and limited exploitation potential (CIS Advisory, Kaspersky).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management