Executive brief
A vulnerability in Google Chrome's geometry component could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with a specially crafted webpage using specific mouse or touch gestures, an attacker can spoof parts of the browser's user interface. This could lead to users inadvertently clicking on hidden elements or being misled about the security state of a page.
Technical details
An inappropriate implementation in the Geometry component of Google Chrome prior to version 150.0.7871.47 allowed for UI spoofing. A remote attacker could exploit this by hosting a crafted HTML page and enticing a user to perform specific UI gestures (such as clicks or drags). This interaction allows the attacker to misrepresent or overlay browser UI elements, potentially leading to clickjacking or other social engineering attacks. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched