CVE-2026-13865
published 2026-06-30CVE-2026-13865: Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted…
PriorityP421medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.24%
14.9th percentile
Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13865
vendor_chrome·2026-06-30
CVE-2026-13865 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-13865
Stable Channel Update for Desktop
CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. Reported by Google on 2026-03-28 [N/A][ 497207698 ] Medium CVE-2026-13866: Insufficient validation of untrusted input in Input
Reported by Google on 2026-03-28 [N/A][ 497345177 ] Medium CVE-2026-13867: Inappropriate implementation in Geolocation
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2026-13864
vendor_chrome·2026-06-30·CVSS 8.1
CVE-2026-13864 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-13864
Stable Channel Update for Desktop
CVE-2026-13864: Insufficient policy enforcement in WebHID. Reported by Google on 2026-03-26 [N/A][ 497090912 ] Medium CVE-2026-13865: Insufficient validation of untrusted input in Enterprise
Reported by Google on 2026-03-28 [N/A][ 497207698 ] Medium CVE-2026-13866: Insufficient validation of untrusted input in Input
Severity: medium
Red Hat
chromium-browser: Insufficient validation of untrusted input in Enterprise
vendor_redhat·2026-06-30·CVSS 4.3
CVE-2026-13865 [MEDIUM] chromium-browser: Insufficient validation of untrusted input in Enterprise
chromium-browser: Insufficient validation of untrusted input in Enterprise
Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
An insufficient validation of untrusted input flaw was found in the Enterprise component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=497090912
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
ghsa_unreviewed·2026-07-01
CVE-2026-13865 [MEDIUM] CWE-20 Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-06-30
Published