By weakness (CWE)

CWE-451: related vulnerabilities

CVEs classified under CWE-451. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

99 published vulnerabilities

  • CVE-2026-11172HIGH 8.8

    A UI spoofing flaw in Chrome's Contact Picker on Android allows attackers to trick users via specially crafted web pages. When a user attempts to select a contact, a malicious site can mask its true identity or intentions by manipulating the security UI elements that normally help users understand what app or service is asking for contact information. This deceives users into granting access to their contacts under false pretenses.

  • CVE-2026-11175HIGH 8.8

    Google Chrome on Android contains a flaw in how it displays security-related UI elements within the Messages feature. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security dialogs or warnings, when they're actually seeing fake ones controlled by the attacker. This UI spoofing attack requires user interaction—the victim must visit the malicious page—but once they do, the attacker can deceive them into taking actions they wouldn't normally take, such as entering credentials or approving permissions.

  • CVE-2019-25718HIGH 8.4

    The Dräger Infinity Explorer C700, a patient monitor interface device, contains a vulnerability that allows an attacker with local access to break out of its restricted kiosk environment and gain full control of the underlying operating system. Once escaped from kiosk mode, an attacker can manipulate the device's display, causing it to show incorrect patient data or no data at all—a serious concern in clinical settings where accurate vital sign monitoring is critical to patient safety.

  • CVE-2026-53829HIGH 8.0

    OpenClaw versions prior to 2026.5.18 suffer from a display truncation flaw that allows authenticated users to deceive approval workflows. An attacker can craft oversized commands with innocent-looking prefixes that pass review, but hidden malicious suffixes execute after approval is granted. This bypasses the human review step that should catch unauthorized operations.

  • CVE-2026-0088HIGH 7.8

    A flaw in Android's certificate installer component allows a malicious app with basic system privileges to bypass security dialogs that normally protect sensitive operations. By exploiting misleading UI presentation, an attacker can escalate their permissions without user knowledge or interaction. The vulnerability is particularly dangerous because it requires no special execution rights—a standard app can trigger it.

  • CVE-2026-0093HIGH 7.8

    CVE-2026-0093 is a local privilege escalation vulnerability affecting Google Android. The flaw stems from misleading user interface elements that obscure the true nature of certain operations, potentially tricking users into granting elevated permissions. An attacker with local access to the device can exploit this weakness to escalate privileges without needing special system permissions beforehand, and notably, without requiring any user interaction during the actual exploitation phase. The vulnerability allows an attacker to read, modify, or delete sensitive data and potentially take control of affected system functions.

  • CVE-2026-0094HIGH 7.8

    A flaw in Android's KeyChain component allows a local attacker with user-level privileges to manipulate the certificate approval interface in a way that tricks the system into granting access to certificates without explicit user consent. The vulnerability stems from misleading or incomplete UI messaging in the getApplicationLabel function, enabling privilege escalation entirely through local interaction. No special permissions or user action is required to exploit it once initiated.

  • CVE-2026-0096HIGH 7.8

    CVE-2026-0096 is a local privilege escalation vulnerability in Android's ForgetDeviceDialogFragment that allows an attacker with local access to manipulate or bypass a device-forget confirmation flow due to misleading UI elements. The vulnerability requires no user interaction to exploit and can result in unauthorized privilege escalation on the affected device.

  • CVE-2026-14114HIGH 7.5

    Google Chrome on Android versions prior to 150.0.7871.47 contain a flaw in how the WebAppInstalls feature handles certain file types. An attacker with local access to a device can exploit this to make the browser display fake buttons, warnings, or interface elements that trick users into taking unwanted actions. While the underlying severity designation from Google's security team is 'Low,' the CVSS score reflects the potential for integrity impact if a user is socially engineered through the spoofed UI.

  • CVE-2026-11001MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Payments feature that allows attackers to create a fake user interface through a specially crafted webpage. To exploit this, an attacker would need to trick a user into performing specific interactions—such as clicks or gestures—on the malicious page. The attack does not steal data or crash the browser, but instead deceives the user by making the browser display content that appears to come from a trusted source, when it actually originates from the attacker. This is a medium-severity issue that depends on user interaction to succeed.

  • CVE-2026-11019MEDIUM 6.5

    A vulnerability in Google Chrome's payments implementation on Android allows an attacker who has already compromised the browser's rendering engine to trick users into believing they are interacting with a legitimate website when they are actually on a fraudulent one. The attacker would craft a deceptive HTML page that spoofs the domain name displayed to the user, potentially leading to credential theft, payment fraud, or other social engineering attacks. This requires an initial compromise of the renderer process, which limits the immediate exposure but represents a serious escalation risk once that initial foothold is established.

  • CVE-2026-11215MEDIUM 6.5

    A flaw in how Google Chrome handles domain names on Android devices allows attackers to trick users into visiting fake websites that appear legitimate. By crafting a specially formatted domain name, an attacker can make Chrome display a spoofed address bar, convincing users they're on a trusted site when they're actually on a malicious one. The vulnerability requires user interaction—the victim must visit a link or be socially engineered—but poses a direct threat to credential theft and phishing campaigns.

  • CVE-2026-11222MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser's tab strip displays security information to users. An attacker can craft a malicious webpage that tricks the browser's security UI, making it appear as though the user is visiting a legitimate website when they are actually on a attacker-controlled domain. This is a user-interface spoofing vulnerability that relies on tricking the visual indicators users depend on to verify they're on the correct website.

  • CVE-2026-11225MEDIUM 6.5

    Google Chrome before version 149.0.7827.53 contains a flaw that allows attackers to perform domain spoofing—making a malicious website appear to come from a trusted domain. An attacker would need to trick a user into visiting a crafted link, but once clicked, the browser's address bar or other visual indicators could misrepresent the true origin of the site. This affects Chrome on Windows, macOS, and Linux.

  • CVE-2026-11227MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it displays security information in tab hover cards—the small popup that appears when you hover over a browser tab. An attacker can craft a deceptive domain name that, when displayed in this hover card, makes it appear to be a legitimate website you trust. This is a domain spoofing attack: the user sees what looks like one domain but is actually visiting a different one. The vulnerability requires user interaction (hovering over the tab and being deceived) but could help an attacker trick users into thinking they're on a safe site when they're not.

  • CVE-2026-13892MEDIUM 6.5

    A flaw in Google Chrome for iOS versions before 150.0.7871.47 allows attackers to steal data from websites you visit while using another site, but only if they can trick you into performing specific gestures on their crafted webpage. The vulnerability does not let attackers modify data or crash your browser—it's limited to unauthorized viewing of cross-origin information.

  • CVE-2026-13985MEDIUM 6.5

    A flaw in Google Chrome's MediaCapture implementation allows attackers who have already compromised the browser's renderer process to trick users into interacting with fake UI elements. The attacker crafts a malicious HTML page that makes legitimate-looking interface components appear where they shouldn't, enabling social engineering attacks. This requires the renderer process to already be compromised, limiting the threat to scenarios where initial access has been established through other means.

  • CVE-2026-13988MEDIUM 6.5

    A vulnerability in Google Chrome's Paint feature allows attackers to trick users with fake visual elements on web pages. An attacker could craft a deceptive HTML page that, when visited, displays misleading UI elements—such as fake browser controls or warning dialogs—to manipulate user behavior. This affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking or viewing the page) to be exploited. The attack has no impact on data confidentiality or system availability, but could be used for social engineering, credential theft, or other deception-based attacks.

  • CVE-2026-13996MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw in how it handles permissions that allows an attacker to trick users with a fake webpage. When users visit a malicious site, the browser may display misleading permission prompts or UI elements, making it appear that certain actions have been approved or denied when they actually haven't. This spoofing attack requires user interaction—the victim must visit the crafted page—but does not result in data theft or system crashes.

  • CVE-2026-14002MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles geolocation permissions that allows an attacker who has already compromised Chrome's renderer process to trick users with fake permission dialogs or spoofed UI elements. An attacker would need to first gain control of the renderer process through another vulnerability or attack vector, then exploit this weakness to display misleading geolocation prompts, potentially deceiving users into granting location access they wouldn't otherwise grant.

  • CVE-2026-14014MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw in the Paint component that allows attackers to trick users into seeing a fake or misleading interface. An attacker would host a malicious webpage; when a user visits it, the page can manipulate what appears on screen to mimic legitimate UI elements (buttons, dialogs, login prompts) or hide the true nature of the content. This is a user-interaction vulnerability—the attack requires a victim to visit the crafted page, but no special browser settings or authentication bypass is needed.

  • CVE-2026-14381MEDIUM 6.5

    Google Chrome versions before 150.0.7871.46 contain a flaw in the WebAppInstalls security UI that allows attackers to deceive users through carefully crafted web pages. An attacker can make Chrome's security indicators or install prompts appear fake, potentially tricking users into installing malicious web applications or granting unintended permissions. The vulnerability requires user interaction to exploit but poses a real risk because users rely on Chrome's visual cues to make trust decisions.

  • CVE-2026-14404MEDIUM 6.5

    A flaw in Google Chrome's PDF rendering engine (PDFium) allows attackers to trick users with misleading visual elements in specially crafted PDF files. When you open a malicious PDF, the attacker can manipulate what appears on screen to deceive you about the file's true content or origin—for example, making a phishing document look legitimate. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (opening the PDF) to exploit.

  • CVE-2026-13356MEDIUM 6.3

    A flaw in Firefox for iOS allows a malicious webpage to create a deceptive visual state where the address bar shows one website while the page actually displays attacker-controlled content. This happens when a webpage interrupts a normal navigation by triggering a JavaScript dialog box at precisely the right moment. The browser's UI updates to reflect the legitimate destination, but the attacker's content continues to render behind or within that dialog, tricking users into believing they're on a safe site when they're not.

  • CVE-2026-9106MEDIUM 5.5

    GitHub Enterprise Server contained a vulnerability where an OAuth application scope related to runner management was not displayed to users during authorization. This allowed an attacker to trick a user into granting an application access to manage organization runners without the user's informed consent. The vulnerability affected all versions prior to 3.22 and has been patched in multiple maintenance releases across supported version lines.

  • CVE-2026-10984MEDIUM 5.4

    Google Chrome on Android contains a flaw in how it handles accessibility features that allows attackers to trick users with a fake interface. By hosting a malicious webpage, an attacker can make Chrome display misleading or fraudulent content that mimics legitimate UI elements, potentially deceiving users into performing unintended actions. The vulnerability requires user interaction—specifically, a user must visit the crafted page—but does not require special privileges or complex setup.

  • CVE-2026-11232MEDIUM 5.4

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the TabGroups feature handles network input, allowing attackers to deceive users through fake or misleading visual elements in the browser interface. An attacker would need to trick a user into visiting a malicious website or intercepting network traffic, but the actual attack surface is relatively narrow—the vulnerability requires user interaction and does not enable data theft or system crashes on its own.

  • CVE-2026-14132MEDIUM 5.4

    A flaw in Google Chrome's WebXR (extended reality) implementation allows attackers to trick users by displaying fake UI elements on web pages. An attacker crafting a malicious HTML page can exploit this to make users believe they're interacting with legitimate interface elements when they're actually interacting with attacker-controlled content. This requires user interaction and doesn't affect data confidentiality or system availability, but can be used for phishing or social engineering attacks.

  • CVE-2026-14142MEDIUM 5.4

    A flaw in how Google Chrome handles extensions could allow an attacker who has already compromised your browser's rendering engine to trick you into clicking malicious UI elements by disguising them as legitimate browser controls. The attacker would need to first gain control of the renderer process—typically through a separate vulnerability or compromise—then exploit this weakness to display fake dialogs or buttons that appear to come from Chrome itself. This is a secondary attack that depends on prior compromise.

  • CVE-2026-45488MEDIUM 5.4

    Microsoft Edge (Chromium-based) contains a user interface flaw that allows attackers to misrepresent critical information to users, potentially tricking them into believing they are interacting with a legitimate website or service when they are not. An attacker can exploit this over the network by manipulating what Edge displays, leading to spoofing attacks. The vulnerability requires user interaction—specifically, the user must take an action in the browser—but does not require special privileges or complex setup to attempt. Impact is limited to partial information disclosure and integrity issues; system availability is not affected.

  • CVE-2026-13989MEDIUM 5.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the PageInfo feature displays information to users. An attacker who has already compromised Chrome's rendering engine can craft a malicious webpage that tricks users into believing they are interacting with a legitimate interface element, when in fact they are not. This is a UI spoofing attack—the attacker cannot steal data or crash the browser, but can deceive users about what they're seeing on screen.

  • CVE-2026-14153MEDIUM 5.3

    Google Chrome versions before 150.0.7871.47 contain a UI spoofing vulnerability in the Glic component. An attacker can craft a malicious HTML page that, when viewed by a user who performs specific UI gestures (like clicks or interactions), displays fake interface elements that deceive the user into believing they're interacting with legitimate browser controls or content. This is a social engineering attack that relies on user interaction but can expose sensitive information through misdirection.

  • CVE-2026-14154MEDIUM 4.8

    CVE-2026-14154 is a UI spoofing vulnerability in Google Chrome's DevTools that requires an attacker to trick a user into installing a malicious extension. Once installed, the extension can display fake interface elements to deceive users, potentially leading to credential theft or social engineering attacks. While Google rates this as low severity, the attack chain depends on user action to install the extension, which limits but does not eliminate risk.

  • CVE-2026-11107MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles the Downloads feature that allows an attacker to trick users with a deceptive webpage. Specifically, an attacker could craft a malicious HTML page that, when viewed in an affected Chrome browser, would display fake or misleading interface elements to deceive users—a technique called UI spoofing. The vulnerability requires user interaction (visiting the malicious page) but does not compromise confidentiality or system availability; the primary risk is deception around the integrity of what the user sees on their screen.

  • CVE-2026-11216MEDIUM 4.3

    Google Chrome contains a flaw in how it displays security warnings for file input operations. An attacker can craft a malicious webpage that tricks users into performing specific mouse or keyboard actions—such as clicking or dragging—that trigger the file picker dialog. By manipulating the visual presentation of this dialog, the attacker can deceive the user about what action they're performing, potentially leading them to upload sensitive files or authorize unintended operations. This is a user-interaction vulnerability: it requires the attacker to convince the user to engage in the specific gestures, but once they do, the spoofed UI can create false impression of legitimacy.

  • CVE-2026-11228MEDIUM 4.3

    Google Chrome before version 149.0.7827.53 contains a flaw in how it handles file input operations that allows attackers to deceive users through visual manipulation. If an attacker can trick a user into performing specific clicks or interactions on a malicious webpage, they can spoof the browser interface—making fake buttons, dialogs, or other UI elements appear legitimate. This is a social engineering attack that relies on user interaction; the vulnerability itself is in Chrome's file input implementation.

  • CVE-2026-11245MEDIUM 4.3

    CVE-2026-11245 is a user interface spoofing vulnerability in Google Chrome's payment handling system. An attacker can craft a deceptive HTML page that tricks users into believing they are interacting with legitimate payment dialogs or security prompts, potentially leading to credential theft, social engineering, or other forms of user deception. The vulnerability requires user interaction (clicking or engaging with the malicious page) to be exploited, limiting its scope but not eliminating risk in realistic phishing or drive-by attack scenarios.

  • CVE-2026-11254MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a UI spoofing vulnerability in its permissions implementation. An attacker can craft a malicious HTML page that, when visited by a user, displays fake permission prompts or other interface elements to deceive users into granting access or performing unintended actions. The attack requires user interaction—specifically, the victim must visit the attacker's page—but does not require any special browser configuration or privilege level.

  • CVE-2026-11285MEDIUM 4.3

    Google Chrome on iOS versions before 149.0.7827.53 contain a flaw that allows attackers to trick users with fake, spoofed user interface elements embedded in malicious web pages. An attacker would need to convince a user to visit a crafted HTML page, but no special privileges are required and the attack can be delivered over the network. The vulnerability does not compromise data confidentiality or availability, but could deceive users about what they are viewing or interacting with.

  • CVE-2026-11286MEDIUM 4.3

    A flaw in Google Chrome's Wallet component allows attackers who have already compromised a browser's renderer process to trick users with fake UI elements displayed on a web page. This requires the attacker to first gain control of the renderer—the part of the browser that displays web content—which is a significant prerequisite but not impossible in real-world scenarios where other vulnerabilities or social engineering may be chained together.

  • CVE-2026-11294MEDIUM 4.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in password handling that allows attackers to create fake or misleading login screens through specially crafted web pages. An attacker would need to trick a user into visiting a malicious website, but once there, the browser's UI protections don't adequately prevent visual deception. This is not an authentication bypass—it's a user interface trick that could mislead people about whether they're interacting with legitimate Chrome UI or attacker-controlled content.

  • CVE-2026-11300MEDIUM 4.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles permissions that allows an attacker to trick users with a specially crafted web page. The attack doesn't steal data or crash the browser—instead, it displays fake permission dialogs or UI elements that might convince a user to grant access they shouldn't. The attacker needs the victim to visit the malicious page, but no special user configuration is required beforehand.

  • CVE-2026-13837MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in CSS handling that allows attackers to deceive users through visual spoofing. By crafting a malicious HTML page, an attacker can trick the browser into displaying fake UI elements—such as bogus address bars, dialogs, or buttons—that appear legitimate but are actually part of the webpage content. This could enable phishing attacks or social engineering by making malicious content look like trusted browser or website elements.

  • CVE-2026-13842MEDIUM 4.3

    Google Chrome for iOS versions prior to 150.0.7871.47 contain a flaw that allows attackers to trick users by forging what appears in the browser's address bar (Omnibox). An attacker can craft a deceptive HTML page that makes it look like you're visiting a legitimate website when you're actually on a malicious one. This is a spoofing vulnerability—the attacker doesn't gain access to your data or crash your device, but can deceive you about where you actually are on the web.

  • CVE-2026-13867MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in the Geolocation feature that allows attackers to deceive users through fake UI elements. By crafting a malicious HTML page, a remote attacker can manipulate what users see on screen—a technique known as UI spoofing—without requiring any special system access or authentication. The attack requires user interaction, such as visiting a compromised website, but does not result in data theft or system compromise.

  • CVE-2026-13902MEDIUM 4.3

    A flaw in Google Chrome for iOS allows an attacker to trick users by making fake content appear in the browser UI. An attacker would need to craft a malicious webpage and convince a user to visit it; the browser would then display misleading interface elements that could be mistaken for genuine browser controls or trusted content. This is a medium-severity issue that affects user trust and could enable phishing or social engineering attacks.

  • CVE-2026-13912MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the Safe Browsing feature validates and displays security information. An attacker can craft a malicious web page that tricks users by spoofing the browser's user interface—making it appear as though Chrome is displaying legitimate security warnings or information when it is not. This deceives users into taking actions they would not normally take, such as entering credentials or downloading files. The vulnerability requires user interaction (visiting the malicious page) to be exploited.

  • CVE-2026-13916MEDIUM 4.3

    A vulnerability in Chrome for iOS allows an attacker to trick users into believing they are seeing legitimate content or UI elements when they are actually viewing a forged interface. An attacker would craft a specially designed web page and serve it to a user; if the user visits the page, the attacker could spoof the browser's user interface—for example, making a phishing page look like a legitimate login screen. This affects Chrome versions prior to 150.0.7871.47 on iOS devices. The attack requires user interaction (visiting the malicious page) but no special permissions or system access.

  • CVE-2026-13941MEDIUM 4.3

    Google Chrome on Android contains a flaw in how it handles SiteSettings that allows attackers to deceive users visually through a specially crafted web page. An attacker can craft HTML that tricks Chrome's interface into displaying misleading information to the user—for example, making it appear that a dangerous permission has been denied when it was actually granted, or vice versa. This is a social engineering vector that relies on user interaction (visiting the malicious page) but does not require special browser permissions or system privileges to execute.

  • CVE-2026-13960MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the password management system that allows attackers to deceive users through visual trickery. By crafting a malicious web page, an attacker can make Chrome's interface appear to show something it isn't—for example, a legitimate password prompt or security warning—fooling users into taking actions they wouldn't normally take. This is a UI spoofing attack: the attacker doesn't break into systems directly, but manipulates what users see on screen to trick them into compromising their own credentials or security.

  • CVE-2026-13966MEDIUM 4.3

    Google Chrome contains a flaw in how it handles browser history that allows an attacker to trick users into believing they are viewing legitimate content when they are not. An attacker can craft a malicious webpage that, when visited, spoofs the appearance of the browser's UI—such as the address bar or other interface elements—to deceive users about what site they are actually on or what action they are performing. This requires user interaction (clicking or viewing the page) but does not require any special system privileges. The issue affects Chrome versions before 150.0.7871.47.

  • CVE-2026-13972MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser's Paint component handles HTML rendering that allows attackers to trick users into thinking they're interacting with legitimate interface elements when they're actually viewing spoofed content. An attacker could craft a malicious webpage that, when visited, displays fake buttons, address bars, or other UI elements to deceive users into performing unintended actions. The attack requires user interaction—specifically visiting the malicious page—but no special privileges or difficult technical conditions.

  • CVE-2026-13978MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in how the browser enforces policies within its PageInfo component, which displays website permission and security information to users. An attacker can craft a malicious HTML page that tricks users into believing they are interacting with legitimate Chrome UI elements—such as permission prompts or security warnings—when they are actually seeing attacker-controlled content. This UI spoofing attack requires user interaction to succeed but could lead to credential theft, social engineering, or other deceptive practices if the fake UI is convincing enough.

  • CVE-2026-13979MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a UI spoofing vulnerability in the Paint feature. An attacker can craft a malicious HTML page that, when visited by a user, tricks the browser into displaying misleading visual elements—making it appear that legitimate security warnings or interface elements are present when they are not. This is a client-side attack requiring user interaction but poses a real risk of social engineering and credential theft.

  • CVE-2026-13980MEDIUM 4.3

    Google Chrome for iOS versions before 150.0.7871.47 contain a flaw that allows attackers to trick users through misleading user interface elements. An attacker could craft a malicious webpage that, when visited, displays fake Chrome UI components—such as address bars or security indicators—to deceive users into believing they're interacting with legitimate browser elements. This is a spoofing vulnerability that relies on user interaction; attackers must convince someone to visit a crafted page, but no special user permissions or technical sophistication is required on the user's end.

  • CVE-2026-13981MEDIUM 4.3

    Google Chrome on iOS contains a UI spoofing vulnerability that allows attackers to deceive users by manipulating how the browser interface appears. An attacker can craft a malicious HTML page that, when visited, tricks users into believing they're interacting with legitimate UI elements—such as address bars or security warnings—when they're actually viewing attacker-controlled content. This vulnerability requires user interaction (visiting the malicious page) but does not compromise data confidentiality or system availability.

  • CVE-2026-13984MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the TabStrip component's security interface that allows an attacker to deceive users through visual spoofing. By crafting a malicious web page, an attacker can manipulate what the browser displays to make it appear legitimate while performing unwanted actions. The attack requires user interaction—specifically, the user must visit the malicious page—but does not require any special privileges or complex browser configurations to execute.

  • CVE-2026-13987MEDIUM 4.3

    A vulnerability in Google Chrome on Android allows attackers to deceive users through fake security warnings or misleading interface elements. By crafting a malicious HTML page, a remote attacker can make Chrome's security UI appear different from what it actually is—for example, displaying a fake warning dialog or masking the real address bar—to trick users into trusting untrustworthy content or performing unintended actions. The attack requires user interaction (clicking or viewing the page) but no special privileges. This affects Chrome versions prior to 150.0.7871.47 on Android devices.

  • CVE-2026-13994MEDIUM 4.3

    Google Chrome on Android contains a flaw in how it manages user credentials that allows attackers to trick users with fake authentication dialogs or credential prompts. An attacker hosting a specially crafted website could deceive users into believing they're interacting with legitimate Chrome security features, potentially leading to credential theft or other user manipulation. The vulnerability requires user interaction—specifically visiting a malicious webpage—but poses a real risk because users generally trust browser UI elements.

  • CVE-2026-14013MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in how SVG (Scalable Vector Graphics) content is handled that allows attackers to trick users through misleading visual elements on a web page. An attacker would need to host a specially crafted HTML page and convince a user to visit it; once there, the vulnerability could be exploited to display fake UI elements—such as fake login prompts or warning dialogs—that appear to come from Chrome or a trusted application. This is primarily a user-trust issue rather than a direct system compromise.

  • CVE-2026-14031MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the file input component handles user interactions, enabling attackers to deceive users through visual spoofing attacks. A malicious HTML page can trick users into believing they are interacting with legitimate browser UI elements when they are not, potentially leading to unintended actions or credential harvesting through deceptive interface overlays.

  • CVE-2026-14042MEDIUM 4.3

    A vulnerability in Google Chrome's Isolated Web Apps feature allows attackers to deceive users through visual manipulation. By sending a specially crafted HTML page, an attacker can spoof the browser's user interface—for example, making a fake login prompt or warning appear legitimate. The attacker cannot steal data or crash the browser, but can trick users into performing actions they wouldn't normally take. This affects Chrome versions before 150.0.7871.47.

  • CVE-2026-14072MEDIUM 4.3

    Google Chrome contains a flaw in how it implements the SplitView feature that allows attackers to trick users by making malicious web content appear as legitimate browser UI elements. An attacker hosting a specially crafted web page can exploit this to perform UI spoofing—essentially overlaying fake buttons, address bars, or other interface elements—potentially deceiving users into taking actions they didn't intend. The vulnerability requires user interaction (visiting a malicious site) to exploit and does not allow data theft or system crashes, but the deception risk is real enough to warrant attention.

  • CVE-2026-14077MEDIUM 4.3

    Google Chrome on macOS contains a flaw in how it handles the Select element that allows attackers to trick users by making the browser's address bar (Omnibox) display fake URLs. An attacker would craft a malicious webpage that, when visited, could make it appear that the user is on a legitimate site when they're actually somewhere else. This is a spoofing vulnerability that relies on user interaction—the victim must visit the malicious page—but requires no special privileges to exploit.

  • CVE-2026-14110MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in the Dark Mode feature that allows an attacker to deceive users through crafted web pages. By manipulating how Dark Mode renders interface elements, an attacker could trick users into believing they are interacting with legitimate browser controls or content when they are not. This is a client-side UI spoofing vulnerability that requires user interaction to exploit.

  • CVE-2026-14123MEDIUM 4.3

    Chrome on iOS versions before 150.0.7871.47 contain a flaw in how the browser's address bar (Omnibox) displays security information. An attacker can craft a malicious webpage that tricks the browser into showing a fake URL in the address bar, making it appear as though you're visiting a legitimate site when you're actually on an attacker's domain. This is a spoofing vulnerability that exploits the visual trust signals users rely on to verify they're on the correct website.

  • CVE-2026-14126MEDIUM 4.3

    Google Chrome on Android has a flaw in how it displays security information to users. An attacker could create a malicious webpage that tricks users into thinking they're visiting a legitimate website when they're actually on the attacker's site. This happens because Chrome isn't properly validating or displaying domain information in certain scenarios. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but doesn't directly expose sensitive data or break the browser's core security model.

  • CVE-2026-14127MEDIUM 4.3

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser handles printing functionality that could allow an attacker to trick users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to have first compromised the Chrome renderer process—the sandboxed component responsible for displaying web content—and then use a specially crafted webpage to create a fake or misleading user interface. While the underlying issue is classified as low severity by the Chromium project, the CVSS scoring reflects the user interaction required and the limited scope of potential impact.

  • CVE-2026-14128MEDIUM 4.3

    A flaw in Google Chrome for iOS allows attackers to trick users by making the browser's address bar (Omnibox) display a fake URL. An attacker would craft a malicious web page and trick a user into visiting it; when the user views the address bar, they see a spoofed URL instead of the actual malicious site they're on. This leverages a user interaction requirement—the victim must actively look at the URL bar—which limits the immediate risk, but the deception could enable phishing or social engineering attacks.

  • CVE-2026-14130MEDIUM 4.3

    Google Chrome versions before 150.0.7871.47 contain a flaw in the browser's address bar (Omnibox) security indicators that allows an attacker to deceive users through visual spoofing. When a user visits a malicious webpage, the attacker can craft HTML content that makes the browser's security UI display false information—such as misleading indicators about the site's legitimacy or HTTPS status. The vulnerability requires user interaction (visiting the crafted page) but does not directly compromise data confidentiality or system availability; the primary risk is user deception leading to credential theft or other social engineering attacks.

  • CVE-2026-14134MEDIUM 4.3

    Google Chrome on Android has a flaw in its Autofill feature that allows an attacker to trick users with fake interface elements on a malicious webpage. An attacker could craft a page that mimics Chrome's autofill UI to deceive users into entering or confirming sensitive information, but the attack requires user interaction and is limited to Android devices running Chrome versions before 150.0.7871.47. The vulnerability does not involve data theft or system crashes, but focuses on visual deception.

  • CVE-2026-14136MEDIUM 4.3

    Google Chrome on iOS versions before 150.0.7871.47 contain a UI spoofing vulnerability that allows attackers to deceive users through a crafted web page. The vulnerability stems from inadequate input validation, enabling malicious actors to manipulate the browser interface in ways that mislead users about the actual content or origin of what they're viewing. While the underlying severity is rated Low by Chromium, the CVSS score of 4.3 reflects the human interaction requirement and limited direct impact—this is primarily a social engineering vector rather than a system compromise threat.

  • CVE-2026-14141MEDIUM 4.3

    Google Chrome on Android has a flaw in how it displays security information when using the Document Picture-in-Picture feature. An attacker can craft a webpage that tricks users into believing they're visiting a legitimate website when they're actually on a malicious one. This happens because the security indicator that normally shows you the real domain being visited can be hidden or spoofed. The vulnerability affects Chrome versions before 150.0.7871.47 on Android devices.

  • CVE-2026-14143MEDIUM 4.3

    Google Chrome on iOS contains a flaw in how it displays password-related security warnings and UI elements. An attacker can craft a malicious webpage that tricks users into thinking they're interacting with legitimate Chrome security prompts when they're actually viewing attacker-controlled content. This UI spoofing could lead users to enter sensitive information or bypass security checks they would otherwise trust. The vulnerability affects Chrome versions before 150.0.7871.47 on Apple iOS devices.

  • CVE-2026-14410MEDIUM 4.3

    A flaw in Google Chrome's Skia graphics library (versions before 150.0.7871.46) allows an attacker who has already compromised the browser's rendering engine to trick users with fake UI elements. The attacker crafts a malicious webpage that, once loaded in an already-compromised renderer, displays spoofed interface components—such as fake address bars or security warnings—to deceive users into taking unwanted actions. The attack requires the renderer process to be compromised first, meaning this is a secondary exploitation technique rather than a standalone attack vector.

  • CVE-2026-45650MEDIUM 4.3

    CVE-2026-45650 is a user interface spoofing vulnerability in Microsoft Bing that allows attackers to misrepresent critical information to users over the network. An attacker can craft a malicious link or interaction that tricks Bing's UI into displaying false or misleading content, potentially leading users to believe they are viewing legitimate search results, advertisements, or information when they are not. This requires user interaction to succeed, meaning a victim must click a link or engage with the spoofed element.

  • CVE-2026-13857MEDIUM 4.2

    A flaw in Google Chrome's geometry rendering engine allows an attacker to trick users into performing specific on-screen gestures—such as clicking or dragging in particular areas—which enables UI spoofing. By hosting a malicious HTML page, an attacker can make the browser display fake interface elements that appear legitimate, potentially deceiving users into taking unintended actions. The vulnerability requires user interaction and affects Chrome versions before 150.0.7871.47.

  • CVE-2026-13860MEDIUM 4.2

    Google Chrome on Windows contains a flaw in its Autofill security user interface that allows an attacker to trick users into performing specific gestures on a malicious webpage, resulting in UI spoofing. The vulnerability requires user interaction and does not lead to information disclosure, but can allow an attacker to manipulate what appears on screen or degrade application availability. Chrome versions prior to 150.0.7871.47 on Windows are affected.

  • CVE-2026-13895MEDIUM 4.2

    Google Chrome's autofill feature contained a flaw that could allow an attacker to trick users into performing specific actions on a malicious webpage, creating a false appearance of legitimate browser or website content. The vulnerability requires user interaction and is considered moderately severe. Google Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-13907MEDIUM 4.2

    Google Chrome on iOS contains a user interface spoofing vulnerability that could allow an attacker to deceive users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to convince a user to perform specific gestures on a crafted webpage, but does not require the user to have special privileges or for the attacker to have prior network access. Patches are available in Chrome 150.0.7871.47 and later.

  • CVE-2026-13956MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the PageInfo security UI displays information to users. An attacker can craft a malicious HTML page that, when shown to a user alongside specific browser interactions, tricks the user into believing they're interacting with legitimate security information. The attacker must convince the user to perform certain UI gestures to make the spoofing work. The impact is limited to tampering with what the user sees on screen, not to stealing data or causing system crashes.

  • CVE-2026-13973MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI implementation flaw that allows attackers to display fake interface elements—like fake login prompts or warning dialogs—if they can trick users into specific mouse or keyboard interactions on a malicious website. The attacker cannot steal data directly, but can confuse users into revealing passwords or credentials by making the fake UI look legitimate.

  • CVE-2026-13983MEDIUM 4.2

    A vulnerability in Chrome on iOS allows attackers to trick users into believing they are visiting a legitimate website by spoofing the Omnibox (the URL bar that displays the website address). An attacker would need to convince a user to perform specific UI gestures—such as particular taps or swipes—on a crafted webpage to trigger the spoofing. The attack does not grant access to sensitive data but can mislead users about which site they are actually visiting, potentially leading to credential theft or other social engineering attacks. This affects Chrome for iOS versions prior to 150.0.7871.47.

  • CVE-2026-13986MEDIUM 4.2

    A flaw in Google Chrome's Media UI on ChromeOS allows an attacker to deceive users through visual spoofing. By crafting a malicious webpage and convincing a user to perform specific gestures (such as clicks or interactions with media controls), an attacker can make the browser display fake UI elements that trick the user into taking unintended actions. This is a user-interaction dependent vulnerability with limited scope—it doesn't enable direct system compromise but can facilitate phishing, credential theft, or social engineering attacks.

  • CVE-2026-13992MEDIUM 4.2

    Google Chrome on macOS contains a UI implementation flaw that allows attackers to create convincing fake interface elements—a technique known as UI spoofing. An attacker would need to host a malicious webpage and convince a user to interact with specific interface elements in a particular way to trigger the vulnerability. The flaw affects Chrome versions prior to 150.0.7871.47 on macOS. While the attack requires user interaction and deliberate UI manipulation, it can lead to confusion about application state or permissions, potentially tricking users into unintended actions.

  • CVE-2026-13993MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how it displays security warnings during Web App installation. An attacker can craft a malicious webpage that, when a user performs specific interactions (like clicking or gesturing in a particular way), tricks the browser into displaying a misleading security UI. This allows the attacker to spoof a domain—making it appear that a trusted site is actually the attacker's site—potentially deceiving users into entering credentials or trusting malicious content. The attack requires deliberate user interaction and doesn't directly compromise data or system availability, but it can deceive users about what website they're interacting with.

  • CVE-2026-13997MEDIUM 4.2

    Google Chrome on Android contains a flaw in how it displays security warnings for browser extensions. An attacker can craft a malicious webpage that tricks users into performing certain taps or swipes, making the extension security UI appear different than it actually is. This deception (called UI spoofing) could lead users to install or interact with harmful extensions without realizing the danger. The vulnerability requires the attacker to convince a user to perform specific gestures, which makes it moderately difficult to exploit in the wild.

  • CVE-2026-13998MEDIUM 4.2

    Google Chrome on macOS contains a flaw in how it displays security warnings when users interact with file input controls. An attacker could craft a deceptive web page that, when a user performs certain mouse or keyboard actions, disguises malicious activity as a legitimate system dialog. This allows the attacker to trick users into believing they are interacting with Chrome's genuine security interface rather than attacker-controlled content. The vulnerability requires user interaction and specific gestures to exploit, limiting its immediate risk but still representing a meaningful social engineering vector.

  • CVE-2026-14026MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a UI security flaw in the SplitView feature that allows an attacker to trick users into performing certain click or gesture actions on a specially crafted webpage. When exploited, the vulnerability enables UI spoofing—displaying false security indicators or interface elements that mislead the user about what is actually happening in the browser. This could be used in social engineering attacks where an attacker makes the browser appear to show something it isn't, such as a fake security warning or address bar state.

  • CVE-2026-14028MEDIUM 4.2

    A flaw in Chrome for iOS versions before 150.0.7871.47 can be exploited to show users fake security or interface elements. An attacker would need to craft a malicious webpage and convince the user to perform specific touch gestures—such as tapping in particular ways—to trigger the spoofing. The vulnerability doesn't directly steal data or crash the browser, but it could deceive users into thinking they're interacting with legitimate Chrome UI when they're actually viewing attacker-controlled content.

  • CVE-2026-14030MEDIUM 4.2

    A vulnerability in Google Chrome's SplitView feature on Linux allows an attacker to trick users into believing they are visiting a legitimate website by spoofing the address bar. This happens when a user performs certain UI interactions with a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit, making it a limited but real risk to users who fall for social engineering.

  • CVE-2026-14129MEDIUM 4.2

    Google Chrome on Android contains a flaw in how it displays the preview tab interface that allows an attacker to trick users into thinking they're interacting with legitimate content when they're actually looking at a spoofed version. An attacker would need to craft a malicious webpage and convince a user to perform specific touch gestures (like swiping or tapping in particular ways) to trigger the vulnerability. The impact is limited but real: users could be misled about what content they're viewing or interacting with.

  • CVE-2026-14138MEDIUM 4.2

    Google Chrome on Windows contains a UI spoofing vulnerability in its WebAppInstalls feature that could allow an attacker to deceive users through a specially crafted webpage. The vulnerability requires user interaction—specifically, deliberate UI gestures—to be exploited. While the underlying implementation flaw is considered low severity by Google, the CVSS scoring reflects the potential for integrity and availability impacts when successfully exploited.

  • CVE-2026-14139MEDIUM 4.2

    Google Chrome versions prior to 150.0.7871.47 contain a UI spoofing vulnerability in the TabStrip component that could allow an attacker to deceive users through a malicious webpage. The attack requires the victim to perform specific user interface gestures—such as particular mouse or keyboard interactions—making it less likely to succeed in practice than attacks that trigger automatically. The vulnerability affects Chrome across Windows, macOS, and Linux systems.

  • CVE-2026-14144MEDIUM 4.2

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser renders security-related UI elements in the Views framework. An attacker could craft a malicious webpage that, when viewed by a user who performs certain mouse or keyboard interactions, tricks the user into believing they are interacting with legitimate browser UI (like permission dialogs or address bar elements) when they are actually interacting with attacker-controlled content. This is a UI spoofing vulnerability that relies on convincing users to take specific actions on a specially crafted page.

  • CVE-2026-12458LOW 3.1

    Google Chrome versions before 149.0.7827.155 contain a flaw in how the browser handles password-related features that could allow an attacker to extract sensitive data from websites the user has visited. The vulnerability requires an attacker to trick a user into performing specific interactions—such as clicking or gesturing—on a malicious webpage. When exploited, it may leak information that should remain isolated between different websites, but only within the user's current browsing session. The severity is considered low because it demands active user participation and the exposed data scope is limited.

  • CVE-2026-13945LOW 3.1

    This vulnerability affects Google Chrome on Linux systems and involves insufficient controls over how browser extensions are validated. An attacker could create a malicious extension that, once installed by a user, could perform UI spoofing—essentially creating fake interface elements that trick users into thinking they're interacting with legitimate Chrome features. The vulnerability requires user action (installing the extension) to be exploited, making it a social engineering vector rather than a direct technical flaw. Google has addressed this issue in Chrome version 150.0.7871.47 and later.

  • CVE-2026-13948LOW 3.1

    Google Chrome versions prior to 150.0.7871.47 contain a flaw in how it enforces policies on browser extensions. An attacker could convince a user to install a malicious extension, then use that extension to create fake or spoofed user interface elements—making it appear as though the user is interacting with legitimate Chrome features when they are actually engaging with attacker-controlled content. This is a social engineering attack that relies on initial user action to install the extension.

  • CVE-2026-13982LOW 3.1

    Google Chrome's password manager UI can be spoofed by attackers who have already compromised the browser's rendering engine. An attacker who gains control of the renderer process—the component responsible for displaying web content—can craft a malicious HTML page that mimics legitimate Chrome password UI elements, potentially deceiving users into revealing credentials or performing unintended actions. This requires prior compromise of the renderer, which is a significant prerequisite but still represents a real escalation risk once initial access is achieved.