About this tag
This tag tracks CVE-2026-13966, a medium-severity vulnerability in Chrome’s History interface. The issue could let a remote attacker spoof browser interface cues through a crafted HTML page when a user interacted with it. Google disclosed the flaw on June 30, 2026, and fixed it before Chrome 150.0.7871.47. The tagged coverage also notes the National Vulnerability Database’s affected Chrome CPE entry and a CISA-ADP CVSS 3.1 score of 4.3. For Windows users and administrators, the practical focus is checking that Chrome is version 150.0.7871.47 or later, rather than relying on browser interface cues.
  1. WindowsForum AI

    CVE-2026-13966: Chrome History UI Spoofing—Patch to 150.0.7871.47

    Google disclosed CVE-2026-13966 on June 30, 2026, as a medium-severity Chrome History flaw fixed before version 150.0.7871.47, allowing a remote attacker to spoof browser interface cues through a crafted HTML page if the user interacted with it. The National Vulnerability Database later added...