CVE-2026-13994: Chrome Android Credential UI Spoofing Vulnerability – What You Need to Know
Google Chrome on Android contains a flaw in how it manages user credentials that allows attackers to trick users with fake authentication dialogs or credential prompts. An attacker hosting a specially crafted website could deceive users into believing they're interacting with legitimate Chrome security features, potentially leading to credential theft or other user manipulation. The vulnerability requires user interaction—specifically visiting a malicious webpage—but poses a real risk because users generally trust browser UI elements.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-451
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-06
NVD description (verbatim)
Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13994 stems from an inappropriate implementation in Chrome's Credential Management subsystem on Android. The vulnerability exploits insufficient validation or isolation of UI elements, permitting a remote attacker to craft HTML that spoofs legitimate credential-related UI. By serving this malicious content, an attacker can render fake authentication prompts that visually mimic genuine Chrome dialogs. The underlying issue is classified as CWE-451 (User Interface Inconsistency), reflecting the gap between what the user perceives and what the browser actually controls. This flaw was resolved in Chrome version 150.0.7871.47 and later.
Business impact
For organizations managing Android devices and Chrome deployment, this vulnerability presents a social engineering vector. Mobile device users are particularly susceptible to UI spoofing because small screens and varying app designs make it harder to distinguish legitimate from fake prompts. A compromised credential could grant attackers access to corporate email, VPNs, SaaS platforms, or other services reliant on phished authentication. While the CVSS score is moderate (4.3), the business risk depends on your organization's reliance on Android Chrome for accessing sensitive systems and the awareness level of your user population.
Affected systems
Google Chrome on Android versions prior to 150.0.7871.47 are affected. This includes all stable, beta, and dev channel releases below that threshold. Desktop Chrome and Chrome on other platforms are not impacted by this specific flaw. Android users running Chrome should prioritize updating to version 150.0.7871.47 or later. Organizations managing Android devices through MDM should verify minimum Chrome version policies are enforced.
Exploitability
Exploitability is straightforward in execution but requires user interaction. An attacker must trick a user into visiting a malicious website (via phishing email, social media, or other means), then serve a crafted HTML page that spoofs Chrome's credential UI. No browser plugin, extension, or special privilege is needed. However, this is not a zero-click vulnerability—the user must navigate to the attacker's site. The lack of KEV inclusion suggests either limited public exploit activity at time of disclosure or a lower real-world threat density compared to other flaws.
Remediation
Update Google Chrome on Android to version 150.0.7871.47 or later. For enterprise environments, configure MDM policies to enforce automatic updates or block older versions. End users should enable automatic updates in the Google Play Store settings. Additionally, user awareness training on recognizing phishing attempts and validating authentication prompts can reduce the likelihood of successful exploitation.
Patch guidance
Google has patched this issue in Chrome 150.0.7871.47. Users and administrators should verify their current Chrome version in Settings > About Chrome (or About Google Chrome, depending on device). If automatic updates are not enabled, open Google Play Store, navigate to Chrome, and manually trigger an update. Organizations with MDM control should update their minimum Chrome version policy and monitor device compliance reporting to ensure no devices remain on vulnerable releases.
Detection guidance
Detection is challenging without application-layer monitoring or user reporting. Network-based intrusion detection is unlikely to flag this as it relies on HTML content trust issues rather than network exploitation. Monitor for users reporting suspicious credential prompts or unexpected authentication requests. Endpoint detection and response (EDR) tools on Android devices could flag suspicious browser process behavior if available. User education and reporting mechanisms are more practical: establish a clear process for users to report unusual authentication dialogs and verify whether Chrome auto-update is functioning across your fleet.
Why prioritize this
Although the CVSS score is moderate (4.3) and this is not a KEV entry, prioritize patching for organizations with significant Android Chrome usage, particularly in industries handling sensitive data (finance, healthcare, government). The vulnerability's reliance on user interaction and spoofing of UI make it a prime target for social engineering campaigns targeting your organization specifically. Mobile workforce environments and BYOD programs elevate risk. Phishing resilience, not just patch velocity, is critical here.
Risk score, explained
The CVSS 3.1 score of 4.3 reflects a Medium severity rating: the attack vector is network-based (AV:N), attack complexity is low (AC:L), no privileges are required (PR:N), but user interaction is necessary (UI:R). Confidentiality is not impacted (C:N), but integrity is affected (I:L)—the attacker can mislead the user or manipulate their perception of security state. Availability is unaffected (A:N). The score appropriately captures that while the attack is easy to launch and can fool users, the direct system compromise is limited. However, integrity of the user's trust model and potential downstream credential compromise elevate practical risk beyond the numerical score.
Frequently asked questions
Will updating Chrome prevent all phishing attacks targeting my users?
No. This patch closes a specific UI spoofing weakness in Chrome's credential management, but it does not prevent phishing attacks using other techniques—for example, visually convincing fake login pages or social engineering tactics. Patching is necessary but not sufficient; maintain user security awareness training and email filtering.
Do I need to update Chrome on desktop and iOS as well?
This CVE affects Chrome on Android only. Desktop Chrome and Chrome on iOS are not impacted by CVE-2026-13994. However, you should maintain current patches across all platforms as a general security hygiene practice.
What if a user visits a malicious site but does not input credentials—is there still a risk?
The vulnerability enables UI spoofing and deception. If a user sees a fake credential prompt and believes it is legitimate but does not enter information, the immediate risk is minimal. However, the attack demonstrates how easily a user can be fooled, signaling a broader vulnerability in user judgment that attackers can exploit through other avenues.
Is this vulnerability exploited in the wild or is it theoretical?
As of the disclosure date, this vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog, suggesting either limited documented public exploitation or lower prevalence. However, absence from KEV does not mean no threat actors are aware of it—stay vigilant and prioritize patching, especially if your organization is a known target.
This analysis is provided for informational purposes and based on the CVE record published on 2026-06-30. Threat landscape, exploit prevalence, and patch availability may change. Verify all patch version numbers and technical details against official Google Chrome and Android security advisories before deployment. SEC.co assumes no liability for actions taken or not taken based on this content. Your organization's risk tolerance, asset criticality, and threat model should drive prioritization decisions. No guarantee is provided that patching will prevent all attacks exploiting this vulnerability or related social engineering tactics. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10984MEDIUMGoogle Chrome Android UI Spoofing Vulnerability – Medium Severity
- CVE-2026-11001MEDIUMGoogle Chrome UI Spoofing in Payments – Patch Now
- CVE-2026-11019MEDIUMChrome Android Payments Domain Spoofing Vulnerability
- CVE-2026-11107MEDIUMGoogle Chrome UI Spoofing Vulnerability – Patch Guide
- CVE-2026-11215MEDIUMChrome Android Domain Spoofing Vulnerability
- CVE-2026-11216MEDIUMChrome File Input UI Spoofing – Patch to 149.0.7827.53
- CVE-2026-11222MEDIUMChrome Tab Strip Domain Spoofing Vulnerability – Patch Guide
- CVE-2026-11225MEDIUMChrome Domain Spoofing Vulnerability – Patch Guidance