Executive brief
A vulnerability in Google Chrome's permission handling could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into granting sensitive permissions or performing unintended actions by misrepresenting what the browser is actually displaying. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation in the Permissions component of Google Chrome allowed a remote attacker to perform user interface (UI) spoofing. By enticing a user to visit a specially crafted HTML page, an attacker could potentially misrepresent permission prompts or other browser UI elements. This vulnerability is classified by Chromium as 'Low' severity. The issue was addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published.