Executive brief
A vulnerability in Google Chrome's tab interface could allow a malicious website to misrepresent its true web address. This could lead users to believe they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. This type of spoofing is often used in phishing attacks to steal login credentials or sensitive personal information.
Technical details
A domain spoofing vulnerability exists in the Tab Strip component of Google Chrome due to an incorrect security UI implementation. By convincing a user to visit a specially crafted HTML page, a remote attacker can manipulate the browser's interface to display a false domain name. This flaw allows for the bypass of visual security indicators that users rely on to verify the authenticity of a website. The issue is resolved in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome Stable Channel Update 149.0.7827.53
- 2026-06-04: disclosed: CVE published to NVD dataset