Executive brief
A vulnerability in Google Chrome's TabGroups feature could allow a remote attacker to misrepresent or spoof parts of the browser's user interface. This type of flaw is typically used in phishing attacks to trick users into believing they are interacting with a legitimate website or browser element when they are not. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in the TabGroups component of Google Chrome prior to version 149.0.7827.53. The flaw stems from an inappropriate implementation that fails to properly handle or validate specific network-driven UI states. A remote attacker can exploit this by delivering malicious network traffic to a victim's browser, potentially leading to the display of fraudulent interface elements. This is classified by Chromium developers as a Low severity issue. The vulnerability is addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published in NVD.