Executive brief
A security issue in Google Chrome for Android could allow a malicious website to display deceptive information in the browser's messaging interface. This type of flaw, known as UI spoofing, can be used to trick users into performing unintended actions or believing they are interacting with a legitimate service. Users are advised to update their Chrome application to the latest version to resolve this issue.
Technical details
An incorrect security UI implementation in the Messages component of Google Chrome on Android allowed a remote attacker to perform UI spoofing. By enticing a user to visit a specially crafted HTML page, an attacker could manipulate the browser's interface to present misleading information to the user. This vulnerability is categorized as a UI spoofing flaw (CWE-1021) and was addressed in version 149.0.7827.53. The attack requires user interaction (visiting the malicious site) but no special privileges.
Affected products
- Google Chrome for Android prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update announced
- 2026-06-04: disclosed: CVE published to NVD