Executive brief
A vulnerability in Google Chrome's History component could allow a malicious website to spoof parts of the browser's user interface. This could be used to deceive users into performing unintended actions or believing they are on a different, legitimate site. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in Google Chrome's History component due to insufficient policy enforcement. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the browser's user interface. This flaw is categorized by Chromium as Low severity and is addressed in version 149.0.7827.53. The attack requires no special privileges but does require the victim to navigate to a malicious site.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: CVE published to NVD