Executive brief
A security issue in Google Chrome for Android could allow a malicious website to display deceptive information within the browser's Contact Picker interface. This type of flaw, known as UI spoofing, can be used to trick users into performing unintended actions or sharing contact information with the wrong party. Users are protected by updating to the latest version of the Chrome app.
Technical details
A UI spoofing vulnerability exists in the Contact Picker component of Google Chrome for Android. The flaw stems from an incorrect security UI implementation that fails to properly represent the state or origin of the picker interface when triggered by a website. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to overlay or misrepresent the contact selection interface. This could lead to user confusion or the unintended disclosure of contact details. The issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel.
- 2026-06-04: disclosed: CVE published.