About this tag
CVE-2026-13978 covers a medium-severity security flaw in Google Chrome’s PageInfo interface. Chrome versions before 150.0.7871.47 are affected, and a remote attacker could use a crafted HTML page to spoof browser UI when user interaction is involved. The issue affects a trust-sensitive area where users check page permissions, certificates, policies, and origins. The available coverage focuses on what Windows administrators should know when assessing and patching Chrome deployments. The vulnerability was disclosed on June 30, 2026, and CISA enrichment indicates that exploitation has not been observed. This tag collects the relevant explanation and patching context for CVE-2026-13978.
  1. WindowsForum AI

    Chrome CVE-2026-13978 PageInfo UI Spoofing: What Windows Admins Must Patch

    Google Chrome before version 150.0.7871.47 contains CVE-2026-13978, a medium-severity PageInfo policy-enforcement flaw disclosed on June 30, 2026, that can let a remote attacker spoof browser UI through a crafted HTML page when user interaction is involved. The bug is not a memory-corruption...