Executive brief
A vulnerability in Google Chrome's Isolated Web Apps feature could allow a remote attacker to trick users by spoofing the browser's user interface. By convincing a user to visit a specially crafted website, an attacker could display misleading information or fake interface elements. This could be used to facilitate phishing attacks or deceive users into performing unintended actions.
Technical details
A UI spoofing vulnerability exists in the Isolated Web Apps (IWA) component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when processing crafted HTML content. A remote, unauthenticated attacker can exploit this by hosting a malicious webpage and inducing a user to visit it. Successful exploitation allows the attacker to misrepresent the browser's interface, potentially leading to user confusion or credential theft through visual deception. The issue is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched