Executive brief
A vulnerability in Google Chrome for Android could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are interacting with a different site or setting. Users should update to version 150.0.7871.47 or later to resolve this issue.
Technical details
A UI spoofing vulnerability exists in the SiteSettings component of Google Chrome for Android. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when processing certain web content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent browser UI elements, potentially leading to user confusion or social engineering attacks. The issue is addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched