Junglewise Threat Intelligence

CVE-2026-11222: Google Chrome domain spoofing in Tab Strip

CVE-2026-11222 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's tab interface could allow a malicious website to misrepresent its true web address. This could lead users to believe they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. This type of spoofing is often used in phishing attacks to steal login credentials or sensitive personal information.

Technical details

A domain spoofing vulnerability exists in the Tab Strip component of Google Chrome due to an incorrect security UI implementation. By convincing a user to visit a specially crafted HTML page, a remote attacker can manipulate the browser's interface to display a false domain name. This flaw allows for the bypass of visual security indicators that users rely on to verify the authenticity of a website. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome Stable Channel Update 149.0.7827.53
  • 2026-06-04: disclosed: CVE published to NVD dataset

References

Related threats