Executive brief
A security issue in Google Chrome for macOS could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with specific parts of the screen, an attacker can spoof the browser's user interface to hide or misrepresent security information. This could lead to users unknowingly granting permissions or visiting fraudulent sites they believe are legitimate.
Technical details
A UI spoofing vulnerability exists in Google Chrome for macOS prior to version 150.0.7871.47 due to an inappropriate implementation in the user interface components. A remote attacker can exploit this by hosting a specially crafted HTML page and tricking a user into performing specific UI gestures. Successful exploitation allows the attacker to misrepresent or overlap browser UI elements, potentially leading to user confusion or unauthorized actions. The vulnerability is rated as Medium severity by Chromium and has been addressed in the stable channel update.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched