Executive brief
A security issue in Google Chrome's password management interface could allow a malicious website to misrepresent its identity. By tricking the browser's user interface, an attacker could perform domain spoofing, potentially leading users to believe they are interacting with a legitimate site when they are actually on a fraudulent one. This could be used to facilitate phishing attacks or unauthorized credential entry.
Technical details
An incorrect security UI implementation in the Passwords component of Google Chrome allowed a remote attacker to perform domain spoofing. The vulnerability is triggered when a user visits a specially crafted HTML page designed to manipulate how the browser displays origin or security information within the password manager interface. This flaw enables an attacker to bypass certain UI-based security indicators, potentially leading to credential theft through phishing. The issue is resolved in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: CVE published to NVD