Executive brief
A vulnerability in Google Chrome's DigitalCredentials component could allow a malicious website to misrepresent its identity or display deceptive interface elements. This type of 'UI spoofing' can be used to trick users into providing sensitive information or performing unintended actions by mimicking legitimate browser prompts. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists in the DigitalCredentials component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform user interface (UI) spoofing, potentially bypassing security indicators or misrepresenting the origin of a credential request. The vulnerability is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date