Total
325 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-38082 | 1 Microsoft | 1 Edge | 2026-07-20 | N/A | 4.7 MEDIUM |
| Microsoft Edge (Chromium-based) Spoofing Vulnerability | |||||
| CVE-2026-45150 | 2026-07-15 | N/A | N/A | ||
| Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b. | |||||
| CVE-2026-48760 | 1 Sensiolabs | 1 Symfony | 2026-07-15 | N/A | 6.1 MEDIUM |
| Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13. | |||||
| CVE-2026-13356 | 1 Mozilla | 1 Firefox | 2026-07-08 | N/A | 6.3 MEDIUM |
| A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3. | |||||
| CVE-2026-3861 | 1 Linecorp | 1 Line | 2026-07-08 | N/A | 6.5 MEDIUM |
| LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable. | |||||
| CVE-2026-45488 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 5.4 MEDIUM |
| User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-13912 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13902 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13916 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13983 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-06 | N/A | 4.2 MEDIUM |
| Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13994 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14134 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-13987 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Incorrect security UI in Mobile in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14114 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 7.5 HIGH |
| Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low) | |||||
| CVE-2026-14126 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-14141 | 1 Google | 2 Android, Chrome | 2026-07-06 | N/A | 4.3 MEDIUM |
| Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-14028 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-02 | N/A | 4.2 MEDIUM |
| Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-14410 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-13986 | 1 Google | 2 Chrome, Chrome Os | 2026-07-02 | N/A | 4.2 MEDIUM |
| Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14381 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 6.5 MEDIUM |
| Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |||||
