Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its password management component. An attacker who has already partially compromised the browser's rendering engine could use this flaw to trick users by displaying fake or misleading interface elements. This could be used to deceive users into performing unintended actions or revealing information by spoofing the browser's legitimate user interface.
Technical details
A vulnerability exists in Google Chrome's Passwords component due to improper input validation (CWE-20). The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass security boundaries and manipulate the browser's user interface. By serving a specially crafted HTML page, the attacker can perform UI spoofing, potentially misleading the user about the state of their saved credentials or browser security. This issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date