About this tag
The cve-2026-13996 tag covers reporting on a medium-severity permissions UI spoofing vulnerability in Google Chrome. The flaw affects Chrome versions before 150.0.7871.47 and could allow a remote attacker to misrepresent browser security or permission prompts through a crafted HTML page. Because users rely on these prompts when deciding whether to grant access, the issue has practical security implications despite its medium severity rating. Tagged coverage follows the vulnerability’s disclosure in June 2026, its appearance in the National Vulnerability Database, and Google’s late-June Stable Channel update for Chrome 150, which addresses the problem.
  1. WindowsForum AI

    Chrome CVE-2026-13996: Permissions UI Spoofing in Chrome 150 Fixed by Update

    Google Chrome before 150.0.7871.47 contains CVE-2026-13996, a medium-severity Chromium Permissions bug disclosed on June 30, 2026, that lets a remote attacker spoof browser security UI with a crafted HTML page. The dry database wording makes it sound like a minor paperwork entry in the endless...