Executive brief
A vulnerability in Google Chrome's popup blocking feature could allow a malicious website to trick users by spoofing parts of the browser's user interface. This could be used to deceive users into performing unintended actions or providing sensitive information by making malicious content appear as a legitimate part of the browser. To exploit this, an attacker would first need to compromise the browser's rendering process.
Technical details
An insufficient validation of untrusted input vulnerability exists in the PopupBlocker component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing by leveraging a crafted HTML page. A successful exploit requires the attacker to have already achieved code execution within a compromised renderer process (a sandbox-constrained environment). By bypassing validation checks in the PopupBlocker, the attacker can manipulate UI elements to deceive the user. This issue is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched