Executive brief
A vulnerability in Google Chrome's media component could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This issue requires the attacker to have already partially compromised the browser's rendering process, typically through a malicious website. If successful, an attacker could display deceptive information to the user, potentially leading to further social engineering or phishing attacks.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome. A remote attacker who has already achieved a compromise of the renderer process can exploit this flaw via a specially crafted HTML page to perform UI spoofing. This vulnerability is categorized by Chromium as 'Low' severity because it requires a prior compromise of the renderer process as a precondition. The issue was addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update released
- 2026-06-04: disclosed: CVE published