CVE-2026-18009

NONE EPSS 0.15%
Updated Jul 30, 2026
Google
Parameter Value
Affected Versions before 151.0.7922.72
Type CWE-20 (Improper Input Validation)
Vendor Google
Public PoC No

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)

Vulnerable Products

google:chrome