Junglewise Threat Intelligence

CVE-2026-11294: Google Chrome UI spoofing in Passwords

CVE-2026-11294 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management component could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by displaying deceptive overlays. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in the Passwords component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which triggers a UI spoofing condition. This flaw allows the attacker to manipulate or overlay browser interface elements related to password management, potentially leading to user confusion or credential harvesting. The vulnerability is addressed in Chrome version 149.0.7827.53. Interaction with a malicious website is a necessary precondition for exploitation.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats