Executive brief
A vulnerability in Google Chrome's PageInfo interface could allow a malicious website to trick users into performing specific actions by spoofing parts of the browser's security interface. If a user is convinced to interact with a specially crafted webpage, they might be misled about the security status or identity of the site they are visiting. This could be used in phishing attacks to gain trust or facilitate further social engineering.
Technical details
A UI spoofing vulnerability exists in the PageInfo component of Google Chrome. The flaw stems from an incorrect implementation of security UI elements, which can be manipulated by a remote attacker through a crafted HTML page. Exploitation requires a user to perform specific UI gestures, such as clicking or hovering in a particular sequence, which allows the attacker to misrepresent security information to the user. This issue is addressed in Chrome version 150.0.7871.47 and later. The vulnerability is classified by Chromium as Medium severity.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Stable channel update released