Executive brief
A security issue in Google Chrome's 'Tab Hover Cards' feature—the small preview that appears when hovering over a browser tab—could allow a malicious website to misrepresent its true web address. An attacker could use a specially crafted domain name to trick users into believing they are visiting a legitimate site, such as a bank or a trusted service. This type of spoofing is often used in phishing attacks to steal login credentials or sensitive personal information.
Technical details
An incorrect security UI implementation in the Tab Hover Cards component of Google Chrome allowed for domain spoofing. By utilizing a specially crafted domain name, a remote attacker could cause the hover card to display misleading origin information. This vulnerability stems from insufficient validation or rendering logic of internationalized or complex domain names within the hover card UI. An attacker would need to entice a user to visit a malicious site and hover over the tab to trigger the spoofed display. The issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11227 published.