Junglewise Threat Intelligence

CVE-2026-11666: Google Chrome UI spoofing in Input component

CVE-2026-11666 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser handles user input allows a remote attacker to trick users by spoofing parts of the browser's user interface. This could be used to facilitate phishing attacks or mislead users into performing unintended actions by presenting fraudulent information on a specially crafted web page.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Input component of Google Chrome. By convincing a user to visit a maliciously crafted HTML page, a remote attacker can exploit insufficient validation of untrusted input to perform UI spoofing. This allows the attacker to manipulate or misrepresent the browser's user interface elements. The vulnerability is resolved in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-17: disclosed: Reported to Chromium by Google researchers
  • 2026-06-08: patched: Stable channel update released for Desktop
  • 2026-06-09: advisory: NVD publication date

References

Related threats