Executive brief
A security issue in Google Chrome for Android could allow a malicious website to trick users into performing unintended actions. By using specially crafted web pages and convincing a user to interact with specific parts of the screen, an attacker could misrepresent or hide security warnings related to browser extensions. This could lead to a user unknowingly installing or interacting with a malicious extension, potentially compromising their browsing privacy.
Technical details
A UI spoofing vulnerability exists in the Extensions component of Google Chrome for Android prior to version 150.0.7871.47. The flaw stems from incorrect security UI handling, which can be exploited by a remote attacker who convinces a user to engage in specific UI gestures on a crafted HTML page. Successful exploitation allows the attacker to overlap or misrepresent security-critical interface elements. This is categorized by Chromium as Medium severity. The issue is resolved in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched