Executive brief
A vulnerability in Google Chrome's file input handling could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with specific parts of a webpage, an attacker could spoof the browser's user interface. This could lead to users inadvertently uploading files or interacting with elements they believe are part of a legitimate site or browser prompt.
Technical details
An inappropriate implementation vulnerability exists in the File Input component of Google Chrome prior to version 149.0.7827.53. A remote attacker can exploit this by hosting a specially crafted HTML page and tricking a user into performing specific UI gestures. This interaction allows the attacker to perform UI spoofing, potentially misrepresenting browser or site elements to the user. The vulnerability is classified by Chromium as Low severity and requires user interaction to be successful. A fix is available in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-06-04: disclosed: CVE published to the NVD.