Executive brief
Google Chrome is a widely used web browser. A vulnerability in its printing component could allow a malicious website to trick users by spoofing parts of the browser's user interface. This could be used to deceive users into performing unintended actions or providing sensitive information, though it requires the attacker to have already partially compromised the browser's internal rendering process.
Technical details
An inappropriate implementation vulnerability exists in the Printing component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform user interface (UI) spoofing. By leveraging a specially crafted HTML page, the attacker can manipulate browser UI elements to deceive the user. This vulnerability is categorized by Chromium as Low severity and is addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory