Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17970

CVE-2026-17970: Google Chrome UI Spoofing Vulnerability

CVE-2026-17970 is a UI spoofing vulnerability in Google Chrome's Passwords feature that allows network attackers to deceive users through malicious traffic. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-17970 Overview

CVE-2026-17970 is an input validation vulnerability in the Passwords component of Google Chrome. Versions prior to 151.0.7922.72 fail to properly validate untrusted input processed by the Passwords feature. An attacker in a privileged network position can leverage malicious network traffic to perform user interface (UI) spoofing against the browser. Chromium classifies the security severity as Low. The weakness is categorized under CWE-20: Improper Input Validation.

Critical Impact

An attacker with a privileged network position can spoof browser UI elements tied to the Passwords feature, potentially misleading users about credential prompts or password-related interactions.

Affected Products

  • Google Chrome (Desktop) versions prior to 151.0.7922.72
  • Chromium-based browsers incorporating the vulnerable Passwords component
  • Downstream distributions that had not yet integrated the Stable channel update

Discovery Timeline

  • 2026-07-30 - CVE-2026-17970 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17970

Vulnerability Analysis

The flaw resides in the Passwords component of Google Chrome. The component processes network-influenced data without sufficient validation of the untrusted input. An attacker positioned between the browser and its network peers can craft malicious traffic that manipulates how the Passwords UI is rendered or presented to the user. The result is a UI spoofing condition, where the browser displays misleading interface elements related to password handling. This can trick users into interacting with attacker-controlled content while believing they are engaging with a legitimate Chrome prompt.

Root Cause

The root cause is improper input validation [CWE-20] within the Passwords feature. Chrome does not adequately sanitize or constrain fields carried by network traffic before those fields influence UI rendering. Because the validation is insufficient, attacker-supplied data reaches UI presentation logic and alters what the user sees. Refer to the Chromium Issue Tracker Entry for implementation-level context.

Attack Vector

Exploitation requires an attacker in a privileged network position, such as an on-path adversary on a shared network segment, a compromised upstream router, or a hostile Wi-Fi access point. The attacker injects or modifies traffic reaching the browser to trigger the spoofed UI. No arbitrary code execution is involved; the impact is limited to deceiving the user through manipulated interface content. No public proof-of-concept, exploit code, or in-the-wild exploitation has been reported. See the Chrome Blog Update for release-level details.

Detection Methods for CVE-2026-17970

Indicators of Compromise

  • Chrome desktop clients still reporting versions below 151.0.7922.72 in endpoint inventory.
  • Unexpected TLS interception, downgrade attempts, or anomalous certificate presentations on paths used by browsers.
  • User reports of unusual Chrome password prompts appearing outside the context of a legitimate site interaction.

Detection Strategies

  • Query endpoint management data for installed Chrome versions and flag any host below 151.0.7922.72.
  • Correlate browser telemetry with network telemetry to identify sessions traversing untrusted or attacker-controlled network segments.
  • Monitor for anomalies in HTTP/HTTPS traffic that suggest active manipulation of browser-bound responses on shared networks.

Monitoring Recommendations

  • Track Chrome patch compliance across the fleet and alert on drift from the fixed build.
  • Log and review captive-portal and public Wi-Fi usage from managed endpoints where feasible.
  • Instrument SOC workflows to review user reports of suspicious password prompts as potential UI spoofing attempts.

How to Mitigate CVE-2026-17970

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all managed endpoints.
  • Verify Chrome auto-update is enabled and functioning; force relaunch where users defer restarts.
  • Restrict use of untrusted networks for sensitive workflows until patch coverage is confirmed.

Patch Information

Google addressed CVE-2026-17970 in the Chrome Stable channel release documented in the Chrome Blog Update. Upgrading to Chrome 151.0.7922.72 or later remediates the insufficient input validation in the Passwords component.

Workarounds

  • Require a trusted VPN when users connect from untrusted or public networks to reduce exposure to on-path attackers.
  • Enforce HTTPS-only mode in Chrome policy to reduce opportunities for network-based traffic manipulation.
  • Educate users to treat unexpected password prompts with suspicion and to verify the site context before interacting.
bash
# Verify installed Chrome version on Windows, macOS, and Linux endpoints
# Windows (PowerShell)
(Get-Item "$Env:ProgramFiles\Google\Chrome\Application\chrome.exe").VersionInfo.ProductVersion

# macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --version

# Linux
google-chrome --version

# Expected output: 151.0.7922.72 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.