Junglewise Threat Intelligence

CVE-2026-11237: Google Chrome UI spoofing in Media component

CVE-2026-11237 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media component could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This issue requires the attacker to have already partially compromised the browser's rendering process, typically through a malicious website. If successful, an attacker could display deceptive information to the user, potentially leading to further social engineering or phishing attacks.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome. A remote attacker who has already achieved a compromise of the renderer process can exploit this flaw via a specially crafted HTML page to perform UI spoofing. This vulnerability is categorized by Chromium as 'Low' severity because it requires a prior compromise of the renderer process as a precondition. The issue was addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 stable channel update released
  • 2026-06-04: disclosed: CVE published

References

Related threats