Executive brief
A vulnerability in Google Chrome's PDF component could allow a remote attacker to manipulate the browser's user interface. This occurs if an attacker has already compromised the browser's rendering process and lures a user to a specially crafted webpage. Successful exploitation could lead to UI spoofing, potentially tricking users into performing unintended actions or disclosing sensitive information by mimicking legitimate browser elements.
Technical details
This vulnerability is classified as an inappropriate implementation (CWE-20) within the PDF engine of Google Chrome. The flaw requires a pre-condition where the attacker has already achieved code execution within the sandboxed renderer process. From this position, the attacker can leverage a crafted HTML page to trigger UI spoofing. This could allow the attacker to misrepresent browser security indicators or other interface elements to the user. The issue was addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
- 2026-06-05: disclosed: NVD publication date.