Executive brief
A vulnerability in Google Chrome's internal user interface (WebUI) could allow a remote attacker to trick users into believing they are visiting a legitimate website when they are actually on a malicious one. This 'domain spoofing' occurs because the browser does not correctly process certain specially crafted domain names. While the risk is considered low, it could be used in phishing attacks to steal user credentials or sensitive information by mimicking trusted brands.
Technical details
An inappropriate implementation in the WebUI component of Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing. The vulnerability stems from how the browser processes and displays crafted domain names within internal WebUI pages. By enticing a user to navigate to a malicious site or interact with specific content, an attacker could misrepresent the origin of a site, potentially facilitating phishing or other social engineering attacks. This issue is categorized by Chromium as Low severity. Users are advised to update to version 149.0.7827.53 or later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published