CVE-2026-13948
Is CVE-2026-13948 real, exploitable, or a false positive? Here's the community verdict.
signals
public sources
Moderate signals. Triage by your actual exposure and reachability.
baseline read
auto · not a community verdict
Low signal — verdict needed
Few public signals point to active risk. Whether a scanner hit here is a true or false positive depends on your version and config — community verdicts decide.
Based on CVSS · FIRST EPSS
Confirm or dispute →CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2026-13948)<a href="https://www.truepositive.app/cve/CVE-2026-13948"><img src="https://www.truepositive.app/cve/CVE-2026-13948/badge.svg" alt="TruePositive verdict for CVE-2026-13948"></a>Live badge that updates automatically as the community verdict changes.
Community ground truth
Be the first practitioner to weigh in
So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.
🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.
In your experience, is this finding real and exploitable?
awaiting field verdictsCurated baseline: A curated baseline from public sources, shown separately from community verdicts.
No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.
Field notes & remediation
Verdicts are the quick signal. Notes are the evidence and fixes behind them.
- 0
No confirmed in-the-wild exploitation or public exploit was found for this yet.
Add a field note or remediationoptional
Related CVEs
Same weakness: CWE-451.
- CVE-2024-38112HIGH 7.5KEVEPSS 84%
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-43461HIGH 8.8KEVEPSS 52%
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-38082MED 4.7EPSS 0%
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-38093MED 4.3EPSS 0%
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-3861MED 6.5EPSS 0%
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
- CVE-2026-45064MED 6.1EPSS 0%
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.