Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw that could allow a remote attacker to manipulate the browser's user interface. If an attacker has already compromised a specific part of the browser (the renderer), they could use a specially crafted website to trick users by spoofing visual elements. This could lead to users being misled about the security status or origin of a website they are visiting.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the Network component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing, provided they have already achieved code execution within a compromised renderer process. By serving a specially crafted HTML page, the attacker can bypass validation checks to manipulate browser UI elements. The issue was addressed in Google Chrome version 150.0.7871.47 for Windows, Mac, and Linux. The Chromium project assigned this a 'Low' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Stable Channel update published.
- 2026-06-30: patched: Fixed in version 150.0.7871.47.