Executive brief
A vulnerability in Google Chrome's Autofill feature on Windows could allow a malicious website to trick users. By convincing a user to perform specific interactions, an attacker can display misleading interface elements. This could be used to spoof legitimate browser prompts, potentially leading to user confusion or unintended actions.
Technical details
A UI spoofing vulnerability exists in the Autofill component of Google Chrome on Windows. The flaw stems from incorrect security UI handling when processing specific user gestures on a crafted HTML page. A remote attacker can exploit this by inducing a user to interact with a malicious website, allowing the attacker to misrepresent browser interface elements. This is categorized by Chromium developers as a Medium severity issue. The vulnerability is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched