Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-13998

CVE-2026-13998: Google Chrome XSS Vulnerability on Mac

CVE-2026-13998 is a cross-site scripting flaw in Google Chrome on Mac that enables UI spoofing attacks through crafted HTML pages. This article covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-13998 Overview

CVE-2026-13998 is a user interface spoofing vulnerability affecting Google Chrome on macOS prior to version 150.0.7871.47. The flaw resides in the File Input component and is classified under [CWE-451] as incorrect security UI. A remote attacker can craft a malicious HTML page that manipulates the file input control to display misleading security indicators. Exploitation requires the victim to perform specific user interface gestures, which increases attack complexity. Chromium security engineers rated the issue Medium severity, and Google addressed it in the Stable channel update for desktop released in June 2026.

Critical Impact

Attackers can spoof security-relevant UI elements to deceive users into disclosing information or approving unintended file interactions on macOS Chrome installations.

Affected Products

  • Google Chrome on macOS versions prior to 150.0.7871.47
  • Apple macOS platforms running vulnerable Chrome builds
  • Chromium-based deployments incorporating the affected File Input component

Discovery Timeline

  • 2026-06-30 - CVE-2026-13998 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-13998

Vulnerability Analysis

The vulnerability stems from an incorrect security UI implementation in Chrome's File Input handling on macOS. The File Input element normally presents users with a system-controlled file selection dialog and associated security indicators. In vulnerable builds, a crafted HTML page can manipulate this control so that visual cues no longer accurately reflect the underlying security state. This mismatch enables UI spoofing, where the browser renders content that misleads the user about origin, trust, or file selection context. The category aligns with [CWE-451] User Interface Misrepresentation of Critical Information. Attackers rely on the user performing specific gestures such as clicks or drags in a controlled sequence to trigger the deception. The confidentiality impact is none, while integrity and availability impacts are low.

Root Cause

The root cause is improper rendering logic in the File Input control on macOS, which allows attacker-controlled HTML and CSS to overlap or obscure trusted UI elements. The browser fails to enforce visual separation between web content and security-relevant chrome, producing an inconsistent state.

Attack Vector

Exploitation requires an attacker to host a crafted HTML page and lure a victim to interact with it. The victim must perform specific UI gestures for the spoof to succeed. No authentication is required, and the attack occurs entirely over the network through normal web browsing.

Because no verified proof-of-concept code is available, technical exploitation details can be reviewed in the Chromium Issue Tracker Entry.

Detection Methods for CVE-2026-13998

Indicators of Compromise

  • User reports of unexpected file selection dialogs or misleading download prompts in Chrome on macOS
  • Chrome browser version strings below 150.0.7871.47 reported by managed endpoints
  • Web traffic to unfamiliar domains immediately preceding user-reported UI anomalies

Detection Strategies

  • Inventory installed Chrome versions across macOS fleets and flag any build prior to 150.0.7871.47
  • Monitor browser telemetry for pages that repeatedly invoke <input type="file"> alongside overlay elements
  • Correlate user-reported phishing attempts with browsing history to identify malicious HTML delivery infrastructure

Monitoring Recommendations

  • Enable enterprise Chrome reporting to centralize version and extension telemetry
  • Track outbound web traffic for domains hosting suspicious file upload flows
  • Review endpoint EDR alerts for unexpected file writes originating from browser processes

How to Mitigate CVE-2026-13998

Immediate Actions Required

  • Update Google Chrome on all macOS endpoints to version 150.0.7871.47 or later
  • Verify automatic update channels are functional and not blocked by network policy
  • Communicate phishing awareness reminders emphasizing caution with unexpected file dialogs

Patch Information

Google released the fix in the Stable channel update announced on the Google Chrome Update Announcement. Administrators should confirm deployment via chrome://settings/help on managed devices or through enterprise management tooling.

Workarounds

  • Restrict browsing to trusted sites through enterprise URL allowlists until patching completes
  • Deploy Chrome enterprise policies that limit interaction with untrusted file upload forms where feasible
  • Educate users to verify the macOS system file picker window before selecting or dragging files into browser pages

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.