Executive brief
A vulnerability in Google Chrome's password management component could allow a malicious website to misrepresent or spoof parts of the browser's user interface. If a user visits a specially crafted webpage, an attacker could trick them into performing unintended actions or disclosing information by displaying misleading visual cues. This issue primarily impacts the integrity of the browser's interface and user trust during sensitive operations like password entry.
Technical details
An inappropriate implementation vulnerability exists in the Passwords component of Google Chrome prior to version 150.0.7871.47. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which allows the attacker to perform user interface (UI) spoofing. This could be used to misrepresent browser-controlled UI elements to the user. The vulnerability is classified by Chromium as Medium severity. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched