Junglewise Threat Intelligence

CVE-2026-11701: Google Chrome UI spoofing in Guest View

CVE-2026-11701 · Severity: info · CVSS 4.3 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Guest View component could allow a malicious website to misrepresent its identity or content. By tricking a user into visiting a specially crafted webpage, an attacker could spoof parts of the browser's user interface. This could be used to deceive users into performing unintended actions or providing sensitive information under false pretenses.

Technical details

This vulnerability stems from an inappropriate implementation within the Guest View component of the Chromium engine. A remote, unauthenticated attacker can exploit this by hosting a specially crafted HTML page and inducing a user to visit it. The flaw allows for UI spoofing, which can be leveraged to bypass security indicators or misrepresent the origin of content within the browser. The issue is categorized under CWE-20 (Improper Input Validation) and was addressed in Chrome version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-06-08: advisory: Google released the stable channel update fixing the issue.
  • 2026-06-09: disclosed: NVD published the CVE record.

References

Related threats