Junglewise Threat Intelligence

CVE-2026-10984: Google Chrome for Android UI spoofing in Accessibility

CVE-2026-10984 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the accessibility features of Google Chrome on Android could allow a malicious website to spoof the browser's user interface. This could be used to trick users into performing unintended actions or disclosing sensitive information by mimicking legitimate browser prompts or security indicators. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in the Accessibility component of Google Chrome for Android. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when accessibility features are active. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to overlay or manipulate the browser's user interface. This can lead to phishing attacks or unauthorized user actions. The issue is resolved in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats