Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's permission handling could allow a malicious website to spoof parts of the user interface. This could be used to trick users into granting sensitive permissions or performing unintended actions by misrepresenting what the browser is actually doing.
Technical details
A UI spoofing vulnerability exists in the Permissions component of Google Chrome. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the browser's user interface via a specially crafted HTML page. By enticing a user to visit a malicious website, an attacker can misrepresent permission prompts or other UI elements. This could lead to a user inadvertently granting site permissions (such as camera or location access) under false pretenses. The vulnerability is addressed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: CVE published to NVD