Executive brief
A vulnerability in Google Chrome for Windows could allow a malicious website to trick users by spoofing parts of the browser's user interface. This occurs when the browser fails to properly verify data during certain transfer operations, potentially leading to phishing or misleading information being presented to the user. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the DataTransfer component of Google Chrome on Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass security checks and perform UI spoofing via a specially crafted HTML page. This could be used to mislead users into performing unintended actions or disclosing information by misrepresenting browser interface elements. The issue is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched