Junglewise Threat Intelligence

CVE-2026-11107: Google Chrome UI spoofing in Downloads

CVE-2026-11107 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Downloads component of Google Chrome could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are interacting with a legitimate site or file download. Users are advised to update to version 149.0.7827.53 or later to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists within the Downloads component of Google Chrome. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger UI spoofing. This flaw allows the attacker to misrepresent the browser's state or interface elements related to file downloads, potentially leading to user confusion or social engineering attacks. The vulnerability is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats