MEDIUM 4.2

CVE-2026-13860: Chrome Autofill UI Spoofing on Windows (CVSS 4.2)

Google Chrome on Windows contains a flaw in its Autofill security user interface that allows an attacker to trick users into performing specific gestures on a malicious webpage, resulting in UI spoofing. The vulnerability requires user interaction and does not lead to information disclosure, but can allow an attacker to manipulate what appears on screen or degrade application availability. Chrome versions prior to 150.0.7871.47 on Windows are affected.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.2 MEDIUM · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Weaknesses (CWE)
CWE-451
Affected products
2 configuration(s)
Published / Modified
2026-06-30 / 2026-07-01

NVD description (verbatim)

Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-13860 is a UI spoofing vulnerability in Chrome's Autofill feature stemming from incorrect security UI presentation (CWE-451: User Interface (UI) Misrepresentation of Critical Information). The attack chain requires convincing a user to perform specific UI gestures while viewing a crafted HTML page. The vulnerability is network-accessible and does not require authentication or elevated privileges, but the high complexity of user interaction (AC:H) and reliance on user participation (UI:R) significantly limit practical exploitation. The CVSS 3.1 base score of 4.2 reflects low confidentiality impact, minor integrity and availability impacts, and the single-system scope.

Business impact

This vulnerability poses a moderate risk to Chrome users on Windows who handle sensitive credential autofill workflows. An attacker exploiting this could present misleading UI that causes users to enter credentials into unintended fields or leak data through integrity compromise. The impact is limited to individual users performing the specific interaction sequence, not affecting bulk data exfiltration or system compromise. Organizations relying on Chrome for authenticated workflows should prioritize awareness, but this is not a critical business-blocking issue.

Affected systems

Google Chrome on Microsoft Windows running versions prior to 150.0.7871.47 are affected. This includes all Windows editions (Home, Pro, Enterprise) running vulnerable Chrome releases. The vulnerability does not affect Chrome on other operating systems (macOS, Linux, Android, iOS), though users on those platforms should verify their Chrome version independently.

Exploitability

Exploitation requires a remote attacker to craft a specific HTML page and convince a user to interact with it in a particular manner. The attack surface is limited to active web browsing scenarios where a user is targeted with social engineering. No authentication or local access is necessary, but the exploitation barrier is meaningfully elevated by the need for precise user gesture coordination. The vulnerability has not been added to the Known Exploited Vulnerabilities catalog, indicating no evidence of active weaponization in the wild at the time of publication.

Remediation

Users must update Google Chrome to version 150.0.7871.47 or later on Windows. Chrome's automatic update mechanism will deploy this version; users can verify their current version through Settings > About Google Chrome, which will trigger an immediate check and update if needed. No manual workarounds are available; patching is the sole remediation path.

Patch guidance

Ensure Chrome on Windows is set to auto-update (the default configuration). Verify the installed version matches 150.0.7871.47 or higher by navigating to chrome://settings/help. For enterprise deployments using Google Chrome for Business or managed Chrome instances, deploy the patched version through your standard software distribution channel and verify coverage across desktop inventory. Consider prioritizing endpoints where Autofill with sensitive credentials is frequently used.

Detection guidance

Monitor for crafted HTML pages or social engineering campaigns targeting Chrome users with instructions to perform unusual UI gestures in the Autofill context. Network-level detection of the exploit itself is difficult; focus on user education and version compliance scanning. Audit Chrome version inventory across your environment using endpoint management tools (Google Admin Console, MDM, or third-party inventory tools) to identify systems running versions before 150.0.7871.47. Review browser update policies to ensure automatic updates are enabled and functional.

Why prioritize this

This vulnerability merits standard patching priority rather than emergency response. The CVSS score of 4.2 (Medium) reflects the combination of network accessibility, user interaction requirement, and limited impact scope. It is not listed on the Known Exploited Vulnerabilities catalog, reducing immediate exploitation risk. However, organizations should patch within their normal Chrome maintenance windows (typically 1–2 weeks) because Autofill-based social engineering is an active attack vector and the fix is straightforward.

Risk score, explained

The CVSS 3.1 score of 4.2 (Medium severity) is driven by: AV:N (network-accessible, no special position required), AC:H (high complexity due to specific UI gesture requirement), PR:N (no privilege escalation needed), UI:R (user interaction essential), S:U (single system scope), C:N (no confidentiality breach), I:L (minor integrity impact from UI spoofing), A:L (minor availability degradation). The score appropriately reflects that while the attack is remotely deliverable, the attacker's control is constrained by user behavior and the resulting harm is limited to individual compromised sessions, not systemic data loss.

Frequently asked questions

Can an attacker steal my saved passwords through this vulnerability?

No. CVE-2026-13860 is a UI spoofing flaw, not a credential exfiltration vector. An attacker can manipulate what appears on screen to mislead a user into incorrect actions, but the vulnerability itself does not read or transmit saved passwords. However, the spoofed UI might trick a user into manually entering credentials in the wrong place, which is a social engineering risk rather than a technical exploit.

Does this affect Chrome on macOS, Linux, or mobile platforms?

No. The vulnerability is specific to Chrome on Windows prior to version 150.0.7871.47. Chrome on macOS, Linux, Android, and iOS are not affected by this particular UI flaw. Users on other platforms should still keep Chrome updated for other security issues, but this CVE does not apply.

Why is this vulnerability marked Medium and not High or Critical if it affects Autofill?

Autofill is a frequent target for social engineering, but the technical impact of this vulnerability is constrained. Exploitation requires precise user gesture coordination (AC:H), produces no confidentiality breach, and causes only minor integrity and availability degradation. The CVSS vector correctly reflects these limitations. The real risk is social engineering exploitation, not a critical code execution or data theft flaw.

How quickly should we patch this?

Patch within your standard Chrome maintenance cycle, typically 1–2 weeks. This is not a zero-day or actively exploited vulnerability, so emergency patching is not required. However, do not delay indefinitely; enable automatic Chrome updates and verify compliance across your environment to ensure no systems fall behind.

This analysis is provided for informational purposes to help security leaders prioritize patching and vulnerability management. It is not a substitute for the official Google Chrome security advisory or vendor guidance. All version numbers, affected products, and CVSS scores are derived from official CVE records; verify patch availability and applicability to your specific environment against the vendor's official security bulletin. No active exploits for this vulnerability have been confirmed as of the publication date. Organizations should conduct their own risk assessment based on their Chrome deployment scale and user behavior. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).