Executive brief
A vulnerability in Google Chrome on Windows could allow a malicious website to trick users into performing unintended actions through interface spoofing. By convincing a user to interact with specific parts of a web page, an attacker could misrepresent browser security information or installation prompts. This could lead to a user unknowingly installing a malicious web application or interacting with a deceptive interface.
Technical details
An inappropriate implementation in the WebAppInstalls component of Google Chrome on Windows allows for UI spoofing. A remote attacker can exploit this by hosting a specially crafted HTML page and tricking a user into performing specific UI gestures. This flaw enables the attacker to manipulate or overlay browser interface elements, potentially leading to user confusion or unauthorized web app installations. The vulnerability is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched