Executive brief
A vulnerability in Google Chrome's extension system could allow a malicious extension to spoof parts of the browser's user interface. If a user is tricked into installing a specially crafted extension, the attacker could display deceptive information or mimic legitimate browser alerts. This could be used to facilitate phishing attacks or mislead users into performing unintended actions.
Technical details
A vulnerability exists in Google Chrome prior to version 150.0.7871.47 due to insufficient policy enforcement within the Extensions component. An attacker can exploit this by convincing a user to install a malicious, specially crafted Chrome Extension. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user about the browser's state or the origin of displayed content. This issue is mitigated by the requirement for user interaction (installing the extension). The vulnerability is addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Chrome 150.0.7871.47 released