Junglewise Threat Intelligence

CVE-2026-11221: Google Chrome UI spoofing in PointerLock

CVE-2026-11221 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's PointerLock feature could allow a remote attacker to perform user interface (UI) spoofing. This occurs when the browser fails to properly validate input, potentially allowing a malicious website to trick users into performing unintended actions or misinterpreting the state of the browser. To exploit this, an attacker would first need to compromise the browser's renderer process.

Technical details

An improper input validation vulnerability (CWE-20) exists in the PointerLock component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing by leveraging a crafted HTML page. A precondition for this attack is that the renderer process must already be compromised. By bypassing input validation checks in PointerLock, the attacker can manipulate the user interface in ways that could mislead the user. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats