Executive brief
A security issue in Google Chrome on Linux could allow a malicious browser extension to trick users by spoofing parts of the web browser's interface. If a user is persuaded to install a specially crafted extension, the attacker could display misleading information or fake UI elements to facilitate further attacks like phishing. Users should update to the latest version of Chrome to resolve this issue.
Technical details
An insufficient policy enforcement vulnerability exists in the Extensions subsystem of Google Chrome for Linux. The flaw allows a crafted Chrome Extension to bypass UI restrictions and perform interface spoofing. Exploitation requires a user to be socially engineered into installing a malicious extension from the web. Once installed, the extension can manipulate or overlay browser UI elements, potentially leading to credential theft or other user-interaction-based attacks. The issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched