Executive brief
Google Chrome is a widely used web browser. A vulnerability in the PageInfo component, which displays site security and connection details, could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate site or that a connection is secure when it is not, potentially leading to credential theft or phishing.
Technical details
A UI spoofing vulnerability exists in the PageInfo component of Google Chrome due to insufficient policy enforcement. By convincing a user to visit a specially crafted HTML page, a remote attacker can manipulate the browser's UI elements to misrepresent site information. This is categorized by Chromium as a Medium severity issue. The vulnerability is addressed in Chrome version 150.0.7871.47 and later. Attackers require no special privileges other than the ability to serve web content to the victim.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched