Executive brief
A security vulnerability in Google Chrome on Windows could allow a malicious website to trick users by spoofing parts of the browser's user interface. This occurs when a website is able to manipulate how media content is displayed, potentially leading a user to believe they are interacting with a legitimate system or browser prompt. To exploit this, an attacker would first need to compromise a specific background process within the browser.
Technical details
An inappropriate implementation in the Media component of Google Chrome on Windows allowed for UI spoofing. The vulnerability requires a remote attacker to have already compromised the renderer process. By serving a specially crafted HTML page, the attacker can then manipulate the user interface to deceive the user. This issue was addressed in Chrome version 150.0.7871.47 for Windows. The Chromium project classified this as Medium severity.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched