Executive brief
A vulnerability in the Google Chrome Password Manager could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This occurs when the browser processes specially crafted network traffic, potentially leading a user to believe they are interacting with a legitimate site or security prompt. An exploit could be used to facilitate phishing attacks or deceive users into revealing sensitive information.
Technical details
A UI spoofing vulnerability exists in the Password Manager component of Google Chrome prior to version 149.0.7827.53. The flaw stems from improper validation of untrusted input (CWE-20) received via network traffic. A remote attacker can exploit this by delivering malicious network data that causes the browser to display misleading user interface elements. This can be used to perform phishing or other social engineering attacks by misrepresenting the origin or state of the Password Manager. The issue is resolved in version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
- 2026-06-04: disclosed: CVE published.