Executive brief
A vulnerability in the Wallet component of Google Chrome could allow a remote attacker to perform UI spoofing. This means an attacker who has already partially compromised the browser's rendering process could trick a user by displaying deceptive interface elements. Such an attack could be used to mislead users into performing unintended actions or disclosing information by mimicking legitimate browser prompts.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Wallet component of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker who has already compromised the renderer process to perform UI spoofing via a specially crafted HTML page. By providing untrusted input that is insufficiently validated, the attacker can manipulate the user interface to display misleading information. This vulnerability is rated as Low severity by Chromium and requires a prior compromise of the renderer process as a precondition for exploitation.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published in NVD.