Executive brief
Google Chrome, a widely used web browser, contained a flaw in how it displayed security information for browser extensions. An attacker could trick a user into installing a malicious extension that misrepresents its identity or permissions through a fake user interface. This could lead to users unknowingly granting sensitive access to their data or browsing activity to a malicious party.
Technical details
A UI spoofing vulnerability existed in the Extensions component of Google Chrome due to incorrect security UI implementation. By crafting a malicious extension and convincing a user to install it, an attacker could manipulate the visual representation of the extension's security properties or permissions. This flaw is categorized by Chromium as Medium severity. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Exploitation requires user interaction to install the malicious extension.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed