Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Speech component could allow an attacker who has already partially compromised the browser to trick users by displaying fake or misleading interface elements. This type of 'UI spoofing' can be used to facilitate phishing attacks or deceive users into performing unintended actions.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Speech component of Google Chrome. A remote attacker who has already compromised the renderer process can exploit this flaw by using a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user about the state of the browser or the identity of a website. The vulnerability was addressed in version 150.0.7871.47.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched