Executive brief
A vulnerability in Google Chrome's Enterprise component could allow a malicious website to spoof parts of the browser's user interface. By tricking a user into visiting a specially crafted webpage, an attacker could display misleading information or fake prompts to the user. This type of attack is typically used to facilitate phishing or to deceive users into performing unintended actions.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Enterprise component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user about the state of the browser or the identity of the site they are visiting. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched