Executive brief
A vulnerability in Google Chrome's SplitView feature could allow a malicious website to misrepresent or 'spoof' parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are interacting with a different site or system dialogue. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in the SplitView component of Google Chrome due to an inappropriate implementation. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the browser's user interface elements. This flaw allows for the presentation of misleading information to the user, potentially facilitating phishing or other social engineering attacks. The vulnerability is addressed in version 150.0.7871.47 and later. Chromium developers have classified this as a Low severity issue.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory