Executive brief
Google Chrome is a widely used web browser. A vulnerability in the way the browser handles user input allows a remote attacker to trick users by spoofing parts of the browser's user interface. This could be used to facilitate phishing attacks or mislead users into performing unintended actions by presenting fraudulent information on a specially crafted web page.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Input component of Google Chrome. By convincing a user to visit a maliciously crafted HTML page, a remote attacker can exploit insufficient validation of untrusted input to perform UI spoofing. This allows the attacker to manipulate or misrepresent the browser's user interface elements. The vulnerability is resolved in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-17: disclosed: Reported to Chromium by Google researchers
- 2026-06-08: patched: Stable channel update released for Desktop
- 2026-06-09: advisory: NVD publication date