Executive brief
A security issue in Google Chrome's SplitView feature could allow a malicious website to trick users into performing specific actions that misrepresent the browser's user interface. This could lead to UI spoofing, where a user believes they are interacting with a legitimate site or security setting when they are actually interacting with attacker-controlled content. This vulnerability primarily impacts the integrity of the visual security indicators users rely on to browse safely.
Technical details
A UI spoofing vulnerability exists in the SplitView component of Google Chrome due to incorrect security UI handling. A remote attacker can exploit this by hosting a specially crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation allows the attacker to misrepresent or spoof elements of the browser's user interface, potentially leading to user confusion or credential theft through deceptive overlays. The issue is addressed in Google Chrome version 150.0.7871.47 and later. The vulnerability is classified as Low severity by Chromium.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: disclosed
- 2026-06-30: patched