Executive brief
A vulnerability in Google Chrome's Password Manager could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This occurs when the browser fails to properly validate data received over the network, potentially leading to the display of misleading information that could be used in phishing or social engineering attacks. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Password Manager component of Google Chrome. By sending malicious network traffic, a remote attacker can exploit insufficient validation of untrusted input to perform UI spoofing. This could allow an attacker to misrepresent browser-controlled UI elements to a user. The vulnerability is fixed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux. Chromium developers have assigned this a 'Medium' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.