Executive brief
A vulnerability in Google Chrome's file input component could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with a specially crafted webpage, an attacker could spoof parts of the browser's user interface. This could lead to users inadvertently uploading files or being misled about the security state of the page.
Technical details
An incorrect security UI implementation in the File Input component of Google Chrome allowed for UI spoofing. A remote attacker could exploit this by hosting a crafted HTML page and tricking a user into performing specific UI gestures. This vulnerability class involves the browser failing to maintain the integrity of its own interface elements when interacting with web content, potentially allowing an attacker to overlay or misrepresent browser-controlled UI. The issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.