Executive brief
A vulnerability in the Google Chrome web browser could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with specific parts of a web page, an attacker can spoof the browser's user interface to hide security warnings or misrepresent website identity. This could lead to users inadvertently providing sensitive information to a fraudulent site.
Technical details
A UI spoofing vulnerability exists in Google Chrome due to an inappropriate implementation in the user interface components. A remote attacker can exploit this by hosting a specially crafted HTML page and enticing a user to perform specific UI gestures (such as clicking or dragging). Successful exploitation allows the attacker to misrepresent or overlap browser UI elements, potentially leading to origin confusion or the bypass of security indicators. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47